<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Confused about the data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Confused-about-the-data/m-p/49198#M9350</link>
    <description>&lt;P&gt;OK, I see lots of data in the Main file. That's good.&lt;BR /&gt;
I have Windows Intelligence &amp;amp; Windows Management Apps installed. How do I tell them to use the Main index? I see Indexes for WI, but they are empty, I don't think that's correct, but I don't know how to get the data to them.&lt;/P&gt;</description>
    <pubDate>Thu, 29 Nov 2012 19:34:39 GMT</pubDate>
    <dc:creator>SLowry</dc:creator>
    <dc:date>2012-11-29T19:34:39Z</dc:date>
    <item>
      <title>Confused about the data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Confused-about-the-data/m-p/49196#M9348</link>
      <description>&lt;P&gt;I've enabled Forwarding &amp;amp; Receiving to accept input from the Universal Forwarder that I installed on my servers. Using Wireshark I know data is being sent to the Splunk server. I'm confused about the next steps in terms of indexing the data. Where is it being stored on my server? Do I need to add files on the server? How does the data get to them?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2012 16:40:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Confused-about-the-data/m-p/49196#M9348</guid>
      <dc:creator>SLowry</dc:creator>
      <dc:date>2012-11-29T16:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: Confused about the data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Confused-about-the-data/m-p/49197#M9349</link>
      <description>&lt;P&gt;You add data inputs on the Universal Forwarders. The forwarders will read data from these inputs and forward that data to the main Splunk indexer. The indexer stores this data in its index, typically in &lt;CODE&gt;$SPLUNK_HOME/var/lib/splunk&lt;/CODE&gt;, where &lt;CODE&gt;$SPLUNK_HOME&lt;/CODE&gt; usually is &lt;CODE&gt;/opt/splunk&lt;/CODE&gt; in *NIX installations and &lt;CODE&gt;C:\Program Files\Splunk&lt;/CODE&gt; in Windows installations.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2012 18:10:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Confused-about-the-data/m-p/49197#M9349</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-11-29T18:10:37Z</dc:date>
    </item>
    <item>
      <title>Re: Confused about the data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Confused-about-the-data/m-p/49198#M9350</link>
      <description>&lt;P&gt;OK, I see lots of data in the Main file. That's good.&lt;BR /&gt;
I have Windows Intelligence &amp;amp; Windows Management Apps installed. How do I tell them to use the Main index? I see Indexes for WI, but they are empty, I don't think that's correct, but I don't know how to get the data to them.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2012 19:34:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Confused-about-the-data/m-p/49198#M9350</guid>
      <dc:creator>SLowry</dc:creator>
      <dc:date>2012-11-29T19:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: Confused about the data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Confused-about-the-data/m-p/49199#M9351</link>
      <description>&lt;P&gt;That's a separate question regarding those specific apps - best idea would be to post that on its own and tag it correctly, so people with knowledge of those apps (I don't have that, sorry) can see and respond.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2012 19:46:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Confused-about-the-data/m-p/49199#M9351</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-11-29T19:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: Confused about the data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Confused-about-the-data/m-p/49200#M9352</link>
      <description>&lt;P&gt;Slowry - Ayn is right - post your q's re WI and Windows Mgmt as new q's - the tagging system works in your favour and you will be able to see 'related' if not similar q's people have had. The user experience on the App's release page makes for good reading at &lt;A href="http://splunk-base.splunk.com/apps/22315/splunk-app-for-windows"&gt;http://splunk-base.splunk.com/apps/22315/splunk-app-for-windows&lt;/A&gt;&lt;BR /&gt;
Br, Dave&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2012 20:23:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Confused-about-the-data/m-p/49200#M9352</guid>
      <dc:creator>DaveSavage</dc:creator>
      <dc:date>2012-11-29T20:23:20Z</dc:date>
    </item>
    <item>
      <title>Re: Confused about the data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Confused-about-the-data/m-p/49201#M9353</link>
      <description>&lt;P&gt;Thanks. You got me moving in the right direction.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Nov 2012 15:12:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Confused-about-the-data/m-p/49201#M9353</guid>
      <dc:creator>SLowry</dc:creator>
      <dc:date>2012-11-30T15:12:23Z</dc:date>
    </item>
  </channel>
</rss>

