All Apps and Add-ons

Estreamer index goes into main how to change it...

New Member


By default if we do nothing eStreamer eNcore data and information goes directly into the main index

How can i change that in a cluster environnement.


0 Karma


I am not a splunk expert. I am sure there is a slicker / better way to do it but this works for me. I did this on my heavy forwarder that feeds an index cluster.

I copied this from

Where data is written to
disabled = 0
source = encore
sourcetype = cisco:estreamer:data
crcSalt =

I added this to /opt/splunk/etc/apps/TA-eStreamer/local/inputs.conf to overide the default
disabled = 0
source = encore
sourcetype = cisco:estreamer:data
crcSalt =
index = cisco

My cisco:estreamer:data is now going to index cisco instead of index main

Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...