<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data going to main even after set to different index in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Data-going-to-main-even-after-set-to-different-index/m-p/537843#M90135</link>
    <description>&lt;P&gt;Double-check the query and settings.&amp;nbsp; The btool output shown is for source /var/log/messages, but the query is showing source=/var/log/cron.&lt;/P&gt;</description>
    <pubDate>Fri, 29 Jan 2021 14:02:25 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-01-29T14:02:25Z</dc:date>
    <item>
      <title>Data going to main even after set to different index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-going-to-main-even-after-set-to-different-index/m-p/537813#M90129</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have install splunk forwarder in 1 centos device, sending to indexer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the search head, i can see data from this host but the the index is put as Main.&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the app, we have already specify to another index and we verified that the index is created.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.PNG" style="width: 849px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12735i022CB52AA95584D9/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.PNG" alt="1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.PNG" style="width: 930px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12736iE167E55CF305092C/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.PNG" alt="2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Anybody know what am i missing? Already restart splunk services for both host and searchhead.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 09:47:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-going-to-main-even-after-set-to-different-index/m-p/537813#M90129</guid>
      <dc:creator>johnlzy0408</dc:creator>
      <dc:date>2021-01-29T09:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: Data going to main even after set to different index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-going-to-main-even-after-set-to-different-index/m-p/537843#M90135</link>
      <description>&lt;P&gt;Double-check the query and settings.&amp;nbsp; The btool output shown is for source /var/log/messages, but the query is showing source=/var/log/cron.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 14:02:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-going-to-main-even-after-set-to-different-index/m-p/537843#M90135</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-01-29T14:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: Data going to main even after set to different index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-going-to-main-even-after-set-to-different-index/m-p/537856#M90139</link>
      <description>&lt;P&gt;Yea i know, I am just showing an example.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the actual settings.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.PNG" style="width: 576px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12746iB54333B991DC7949/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.PNG" alt="3.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the settings in the inputs.conf. Strangely, this is set to disabled but we are receiving from this source.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 14:36:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-going-to-main-even-after-set-to-different-index/m-p/537856#M90139</guid>
      <dc:creator>johnlzy0408</dc:creator>
      <dc:date>2021-01-29T14:36:35Z</dc:date>
    </item>
    <item>
      <title>Re: Data going to main even after set to different index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-going-to-main-even-after-set-to-different-index/m-p/537858#M90140</link>
      <description>&lt;P&gt;I mean for the /var/log/cron. And strangely, all my /var/logs/messages path are also not sending since this morning. i do not know what i did&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 14:40:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-going-to-main-even-after-set-to-different-index/m-p/537858#M90140</guid>
      <dc:creator>johnlzy0408</dc:creator>
      <dc:date>2021-01-29T14:40:08Z</dc:date>
    </item>
    <item>
      <title>Re: Data going to main even after set to different index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-going-to-main-even-after-set-to-different-index/m-p/537871#M90142</link>
      <description>&lt;P&gt;If you're receiving data for a disabled input then the inputs.conf either has not been loaded (restart the forwarder) or is overridden by another inputs.conf file (btool should show that).&amp;nbsp; The same goes for data being sent to the wrong index.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 16:03:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-going-to-main-even-after-set-to-different-index/m-p/537871#M90142</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-01-29T16:03:03Z</dc:date>
    </item>
  </channel>
</rss>

