<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log keeps sending to index=main in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Log-keeps-sending-to-index-main/m-p/522626#M4525</link>
    <description>&lt;P&gt;Try &lt;EM&gt;btool &lt;/EM&gt;on the source machine to check whether any apps/local inputs.conf configured with index main&lt;/P&gt;&lt;P&gt;Reference : &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.6/Troubleshooting/Usebtooltotroubleshootconfigurations" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.6/Troubleshooting/Usebtooltotroubleshootconfigurations&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 02 Oct 2020 05:47:00 GMT</pubDate>
    <dc:creator>renjith_nair</dc:creator>
    <dc:date>2020-10-02T05:47:00Z</dc:date>
    <item>
      <title>Log keeps sending to index=main</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Log-keeps-sending-to-index-main/m-p/522604#M4524</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I been trying to figure this out for the past 2 days now and I cannot seem to find which config file is making my host send logs to index=main. I have 4 other machines in forward management that have the same application sending logs to the correct index except for this system. It seems to send Application logs to index=main but all other security logs go to index=windows. I double checked the apps folder on that machine&amp;nbsp; and compared it with a machine that is not sending to index main and also did the same in the etc/system/local.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is a single deployment we have a single search head and single indexer.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 23:00:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Log-keeps-sending-to-index-main/m-p/522604#M4524</guid>
      <dc:creator>splunktrainingu</dc:creator>
      <dc:date>2020-10-01T23:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: Log keeps sending to index=main</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Log-keeps-sending-to-index-main/m-p/522626#M4525</link>
      <description>&lt;P&gt;Try &lt;EM&gt;btool &lt;/EM&gt;on the source machine to check whether any apps/local inputs.conf configured with index main&lt;/P&gt;&lt;P&gt;Reference : &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.6/Troubleshooting/Usebtooltotroubleshootconfigurations" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.6/Troubleshooting/Usebtooltotroubleshootconfigurations&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2020 05:47:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Log-keeps-sending-to-index-main/m-p/522626#M4525</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2020-10-02T05:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: Log keeps sending to index=main</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Log-keeps-sending-to-index-main/m-p/522637#M4527</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/59944"&gt;@splunktrainingu&lt;/a&gt;&amp;nbsp;..&lt;BR /&gt;Q -&amp;nbsp;&lt;SPAN&gt;I cannot seem to find which config file is making my host send logs to index=main.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Answers:&lt;BR /&gt;1. on the forwarder(s), you can run the btool command.&lt;/P&gt;&lt;P&gt;2. on the forwarder(s), you can view the inputs.conf file directly and see which log file is sending data to which index.&lt;/P&gt;&lt;P&gt;3. on splunk GUI, when you search for the logs from a host/forwarder, you can list down the source, sourcetype as well.&lt;BR /&gt;for example:&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=main host=UF-hostname | table source sourcetype index _raw _time&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;(PS - i have given around 500+ karma points so far, received badge for that, if an answer helped you, a karma point would be nice!. we all should start "Learn, Give Back, Have Fun")&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2020 07:43:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Log-keeps-sending-to-index-main/m-p/522637#M4527</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-10-02T07:43:22Z</dc:date>
    </item>
    <item>
      <title>Re: Log keeps sending to index=main</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Log-keeps-sending-to-index-main/m-p/522758#M4535</link>
      <description>&lt;P&gt;Thank you! from now on I am going to use this! It was so easy to see for some reason there was a inputs.conf in SplunkUniversalforwarder/etc/app/splunkuniversalforwarder/local/inputs.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I used the command&lt;/P&gt;&lt;PRE&gt;splunk btool inputs list --debug&lt;/PRE&gt;</description>
      <pubDate>Fri, 02 Oct 2020 23:44:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Log-keeps-sending-to-index-main/m-p/522758#M4535</guid>
      <dc:creator>splunktrainingu</dc:creator>
      <dc:date>2020-10-02T23:44:17Z</dc:date>
    </item>
  </channel>
</rss>

