<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Setting indexes on windows universal forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-the-Splunk-universal-forwarders-on-a-Windows/m-p/441754#M77025</link>
    <description>&lt;P&gt;No.&lt;BR /&gt;
On the forwarder you use &lt;CODE&gt;inputs.conf&lt;/CODE&gt; and tell it what &lt;CODE&gt;index&lt;/CODE&gt; value will store the data that you are sending.&lt;BR /&gt;
On the indexers you need to create that matching index with &lt;CODE&gt;indexes.conf&lt;/CODE&gt;.&lt;/P&gt;</description>
    <pubDate>Fri, 25 Jan 2019 17:37:02 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2019-01-25T17:37:02Z</dc:date>
    <item>
      <title>How to configure the Splunk universal forwarders on a Windows machine to send to an index that isn't the main?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-the-Splunk-universal-forwarders-on-a-Windows/m-p/441746#M77017</link>
      <description>&lt;P&gt;Hi All, i am trying to configure the splunk universal forwarders on a windows machine to send to an index that isnt main. I attempted to set index=windows_index in the inputs.comf file in $splunk/etc/system/local/. when i set the index there, and restart the forwarder no logs get to splunk. when removed and restarted again, logs all pour in.&lt;/P&gt;
&lt;P&gt;Is this config setting something to be set in the forwarders?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2022 16:45:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-the-Splunk-universal-forwarders-on-a-Windows/m-p/441746#M77017</guid>
      <dc:creator>TrueMex</dc:creator>
      <dc:date>2022-02-11T16:45:24Z</dc:date>
    </item>
    <item>
      <title>Re: Setting indexes on windows universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-the-Splunk-universal-forwarders-on-a-Windows/m-p/441747#M77018</link>
      <description>&lt;P&gt;Is this index created on the indexer? windows_index. Unless you create the index on the indexer, the events end up no where. &lt;/P&gt;</description>
      <pubDate>Fri, 08 Jun 2018 18:31:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-the-Splunk-universal-forwarders-on-a-Windows/m-p/441747#M77018</guid>
      <dc:creator>pradeepkumarg</dc:creator>
      <dc:date>2018-06-08T18:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: Setting indexes on windows universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-the-Splunk-universal-forwarders-on-a-Windows/m-p/441748#M77019</link>
      <description>&lt;P&gt;Can you share your inputs.conf stanza?  Also, to gpradeepkumarreddy's point, the index needs to exist in the indexers.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jun 2018 19:15:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-the-Splunk-universal-forwarders-on-a-Windows/m-p/441748#M77019</guid>
      <dc:creator>kmorris_splunk</dc:creator>
      <dc:date>2018-06-08T19:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: Setting indexes on windows universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-the-Splunk-universal-forwarders-on-a-Windows/m-p/441749#M77020</link>
      <description>&lt;P&gt;Index exists. I figured out the issue in one machine, i did not denote index="windows_index"&lt;/P&gt;

&lt;P&gt;Also note windows_index is a placeholder before anyone else gets me.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jun 2018 19:18:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-the-Splunk-universal-forwarders-on-a-Windows/m-p/441749#M77020</guid>
      <dc:creator>TrueMex</dc:creator>
      <dc:date>2018-06-08T19:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: Setting indexes on windows universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-the-Splunk-universal-forwarders-on-a-Windows/m-p/441750#M77021</link>
      <description>&lt;P&gt;I figured out one issue and yet another has appeared. I needed to have index="windows_index"  with the index inside "" but while this works on one machine it does not on another. i will update when i have more.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jun 2018 19:19:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-the-Splunk-universal-forwarders-on-a-Windows/m-p/441750#M77021</guid>
      <dc:creator>TrueMex</dc:creator>
      <dc:date>2018-06-08T19:19:59Z</dc:date>
    </item>
    <item>
      <title>Re: Setting indexes on windows universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-the-Splunk-universal-forwarders-on-a-Windows/m-p/441751#M77022</link>
      <description>&lt;P&gt;I think you need to login as Admin for editing inputs.conf file on forwarder system. i.e open the .txt file as run as administrator. &lt;/P&gt;</description>
      <pubDate>Fri, 08 Jun 2018 19:35:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-the-Splunk-universal-forwarders-on-a-Windows/m-p/441751#M77022</guid>
      <dc:creator>raghu0463</dc:creator>
      <dc:date>2018-06-08T19:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: Setting indexes on windows universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-the-Splunk-universal-forwarders-on-a-Windows/m-p/441752#M77023</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;I was about to ask the same question.&lt;/P&gt;

&lt;P&gt;So let me get this clear ....&lt;/P&gt;

&lt;P&gt;In file &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf?utm_source=answers&amp;amp;utm_medium=in-comment&amp;amp;utm_term=inputs.conf&amp;amp;utm_campaign=refdoc"&gt;inputs.conf&lt;/A&gt; from Program Files\Splunk\etc\system\local you need to type in what to index to use on the indexer server ... ??&lt;/P&gt;

&lt;P&gt;And on the server side you need to create an index with the name put in the inputs.conf .... right?&lt;/P&gt;

&lt;P&gt;This inputs.conf can't be from Splunk Universal Forwarder? It has to be from splunk folder?&lt;/P&gt;

&lt;P&gt;Can anyone can give me an example of a inputs.conf that collects win security log and send it to an index called win_sec on a server so called 192.168.1.1:9997&lt;/P&gt;

&lt;P&gt;I have some ideas how it should look but i'm lost in commands .....&lt;/P&gt;

&lt;P&gt;Thank you,&lt;BR /&gt;
Bogdan.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2019 14:31:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-the-Splunk-universal-forwarders-on-a-Windows/m-p/441752#M77023</guid>
      <dc:creator>bogdan_nicolesc</dc:creator>
      <dc:date>2019-01-25T14:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: Setting indexes on windows universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-the-Splunk-universal-forwarders-on-a-Windows/m-p/441753#M77024</link>
      <description>&lt;P&gt;You need to make sure that you have &lt;CODE&gt;windows_index&lt;/CODE&gt; defined in &lt;CODE&gt;indexes.conf&lt;/CODE&gt; on your indexers.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2019 16:47:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-the-Splunk-universal-forwarders-on-a-Windows/m-p/441753#M77024</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-25T16:47:56Z</dc:date>
    </item>
    <item>
      <title>Re: Setting indexes on windows universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-the-Splunk-universal-forwarders-on-a-Windows/m-p/441754#M77025</link>
      <description>&lt;P&gt;No.&lt;BR /&gt;
On the forwarder you use &lt;CODE&gt;inputs.conf&lt;/CODE&gt; and tell it what &lt;CODE&gt;index&lt;/CODE&gt; value will store the data that you are sending.&lt;BR /&gt;
On the indexers you need to create that matching index with &lt;CODE&gt;indexes.conf&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2019 17:37:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-the-Splunk-universal-forwarders-on-a-Windows/m-p/441754#M77025</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-25T17:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: Setting indexes on windows universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-the-Splunk-universal-forwarders-on-a-Windows/m-p/544087#M90815</link>
      <description>&lt;P&gt;Updated inputs.conf file from path "C:\Program Files\SplunkUniversalForwarder\etc\system\default"&amp;nbsp;&lt;/P&gt;&lt;P&gt;[monitor://$SPLUNK_HOME\var\log\splunk]&lt;/P&gt;&lt;P&gt;index =&amp;lt;Your Indexname&amp;gt;&lt;/P&gt;&lt;P&gt;[monitor://$SPLUNK_HOME\var\log\watchdog\watchdog.log*]&lt;/P&gt;&lt;P&gt;index =&amp;lt;Your Indexname&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;</description>
      <pubDate>Tue, 16 Mar 2021 23:56:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-the-Splunk-universal-forwarders-on-a-Windows/m-p/544087#M90815</guid>
      <dc:creator>Bakkar</dc:creator>
      <dc:date>2021-03-16T23:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: Setting indexes on windows universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-the-Splunk-universal-forwarders-on-a-Windows/m-p/584744#M102896</link>
      <description>&lt;P&gt;I did like this in path:&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;$SPLUNK_HOME/etc/system/default/indexes.conf for an Index (wallix)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[wallix]&lt;BR /&gt;repFactor = auto&lt;BR /&gt;homePath = volume:hotwarm/wallix/db&lt;BR /&gt;coldPath = volume:cold/wallix/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/wallix/thaweddb&lt;BR /&gt;tstatsHomePath = volume:hotwarm/wallix/datamodel_summary&lt;BR /&gt;homePath.maxDataSizeMB = 5120&lt;BR /&gt;coldPath.maxDataSizeMB = 10240&lt;BR /&gt;maxHotBuckets = 10&lt;BR /&gt;maxDataSize = auto_high_volume&lt;BR /&gt;maxTotalDataSizeMB = 15360&lt;BR /&gt;maxWarmDBCount = 4294967295&lt;BR /&gt;frozenTimePeriodInSecs = 31104000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2022 14:46:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-the-Splunk-universal-forwarders-on-a-Windows/m-p/584744#M102896</guid>
      <dc:creator>HiwaKarimi</dc:creator>
      <dc:date>2022-02-11T14:46:00Z</dc:date>
    </item>
  </channel>
</rss>

