<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Index main in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Index-main/m-p/476581#M81818</link>
    <description>&lt;P&gt;Did you restart Splunk after making the change?&lt;/P&gt;</description>
    <pubDate>Fri, 10 Jan 2020 13:16:19 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-01-10T13:16:19Z</dc:date>
    <item>
      <title>Index main</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-main/m-p/476578#M81815</link>
      <description>&lt;P&gt;Hello Splunkers!&lt;/P&gt;

&lt;P&gt;I have a question, i have installed a universal forwarder on a AIX server, but all the logs arrives on the index "main", they should be arrive in one especific index that i created. How can i fix this issue and why is this happening? &lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2020 14:43:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-main/m-p/476578#M81815</guid>
      <dc:creator>juls0125</dc:creator>
      <dc:date>2020-01-08T14:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: Index main</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-main/m-p/476579#M81816</link>
      <description>&lt;P&gt;Check the inputs.conf file(s) on  the forwarder to confirm an index is specified for each input.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2020 15:19:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-main/m-p/476579#M81816</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-01-08T15:19:20Z</dc:date>
    </item>
    <item>
      <title>Re: Index main</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-main/m-p/476580#M81817</link>
      <description>&lt;P&gt;i have added the next information on the inputs.conf file without any change (informix is the index)&lt;/P&gt;

&lt;P&gt;[monitor://$SPLUNK_HOME/audit]&lt;BR /&gt;
index = informix&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2020 19:15:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-main/m-p/476580#M81817</guid>
      <dc:creator>juls0125</dc:creator>
      <dc:date>2020-01-08T19:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: Index main</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-main/m-p/476581#M81818</link>
      <description>&lt;P&gt;Did you restart Splunk after making the change?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 13:16:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-main/m-p/476581#M81818</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-01-10T13:16:19Z</dc:date>
    </item>
  </channel>
</rss>

