<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: replaced with new index with old one in inputs.conf in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/replaced-with-new-index-with-old-one-in-inputs-conf/m-p/493084#M84277</link>
    <description>&lt;P&gt;Thanks for the response. Yes, the new index exist on all the indexers and i have restarted the forwarder. checked if the index name has changed on the server by the application team and it has the new index in the inputs.conf but still it is ingesting to the old index.&lt;/P&gt;</description>
    <pubDate>Fri, 04 Oct 2019 15:28:43 GMT</pubDate>
    <dc:creator>sathwikr076</dc:creator>
    <dc:date>2019-10-04T15:28:43Z</dc:date>
    <item>
      <title>replaced with new index with old one in inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/replaced-with-new-index-with-old-one-in-inputs-conf/m-p/493080#M84273</link>
      <description>&lt;P&gt;I have changed the index name for a log ingestion to a new one but the logs are still ingesting to the old index. I cannot understand why the logs are not ingesting to new index. Please let me know if anyone have any idea.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 14:54:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/replaced-with-new-index-with-old-one-in-inputs-conf/m-p/493080#M84273</guid>
      <dc:creator>sathwikr076</dc:creator>
      <dc:date>2019-10-04T14:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: replaced with new index with old one in inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/replaced-with-new-index-with-old-one-in-inputs-conf/m-p/493081#M84274</link>
      <description>&lt;P&gt;Hi sathwikr076,&lt;BR /&gt;
how do you changed destination index? &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;in inputs.conf on Universal Forwarders,&lt;/LI&gt;
&lt;LI&gt;in overriding on Indexers?&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;If on UFs, after update, did you restarted Splunk on UFs?&lt;BR /&gt;
If on Indexers, after update, did you restarted Splunk on Indexers? have you in the middle any Heavy Forwarders?&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 15:08:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/replaced-with-new-index-with-old-one-in-inputs-conf/m-p/493081#M84274</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-10-04T15:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: replaced with new index with old one in inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/replaced-with-new-index-with-old-one-in-inputs-conf/m-p/493082#M84275</link>
      <description>&lt;P&gt;i have changed on UF and restarted the service through deployment server remotely as i do not have access to the server. i checked the internal logs and i can see &lt;BR /&gt;
&lt;STRONG&gt;Metrics - group=per_index_thruput, series="new_index", kbps=0.22774524335479657, eps=0.19367014189230036, kb=7.0556640625, ev=6, avg_age=9110.833333333334, max_age=54545&lt;/STRONG&gt; but still it is ingesting to the old index. i just asked the application team to restart the forwarder directly on the server.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:23:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/replaced-with-new-index-with-old-one-in-inputs-conf/m-p/493082#M84275</guid>
      <dc:creator>sathwikr076</dc:creator>
      <dc:date>2020-09-30T02:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: replaced with new index with old one in inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/replaced-with-new-index-with-old-one-in-inputs-conf/m-p/493083#M84276</link>
      <description>&lt;P&gt;Greetings @sathwikr076,&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Does the index exist on the indexer that the data is being forwarded to?&lt;/LI&gt;
&lt;LI&gt;Did you restart the Splunk forwarder service on the machine that is monitoring the log?&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Cheers,&lt;BR /&gt;
Jacob&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 15:14:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/replaced-with-new-index-with-old-one-in-inputs-conf/m-p/493083#M84276</guid>
      <dc:creator>jacobpevans</dc:creator>
      <dc:date>2019-10-04T15:14:33Z</dc:date>
    </item>
    <item>
      <title>Re: replaced with new index with old one in inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/replaced-with-new-index-with-old-one-in-inputs-conf/m-p/493084#M84277</link>
      <description>&lt;P&gt;Thanks for the response. Yes, the new index exist on all the indexers and i have restarted the forwarder. checked if the index name has changed on the server by the application team and it has the new index in the inputs.conf but still it is ingesting to the old index.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 15:28:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/replaced-with-new-index-with-old-one-in-inputs-conf/m-p/493084#M84277</guid>
      <dc:creator>sathwikr076</dc:creator>
      <dc:date>2019-10-04T15:28:43Z</dc:date>
    </item>
  </channel>
</rss>

