All Apps and Add-ons

Splunk Add-on for Microsoft Windows: How do I specify which index to send data to?

andrewtrobec
Motivator

Hello,

I've just installed the Splunk Add-on for Microsoft Windows and I will be collecting data from UFs that forward first to a HF and then to an indexing cluster.  The app will be deployed to multiple UFs via deployment server.  I only want to collect data from the machines that the UFs are installed on.

I see that there is no way to specify within inputs.conf which index to send the data to.  I've read the documentation but I still don't understand how.  I've even found this post which discusses the same topic but doesn't really provide me with an answer that I understand (sends me to documentation for older version of the add-on).

Could somebody please give me a push in the right direction?

Thank you and best regards,

Andrew

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Specify the destination index in inputs.conf.  Simply insert a new line in the appropriate stanza with index = followed by the name of index.  See the examples at https://docs.splunk.com/Documentation/WindowsAddOn/8.1.2/User/Configuration#Configure_inputs.conf

---
If this reply helps you, Karma would be appreciated.

View solution in original post

andrewtrobec
Motivator

@richgalloway thank you so much, I don't know how I didn't figure that out.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Specify the destination index in inputs.conf.  Simply insert a new line in the appropriate stanza with index = followed by the name of index.  See the examples at https://docs.splunk.com/Documentation/WindowsAddOn/8.1.2/User/Configuration#Configure_inputs.conf

---
If this reply helps you, Karma would be appreciated.

rosez2
Engager

This worked for me when I was testing on a personal Windows laptop, but the official system I use is 2015 Windows 10 Pro, which is much older. I had to download an older 7.2.10 version of Splunk Universal Forwarder for it to even download. The logs are  being forwarded, but when I add the index line, nothing changes and the search for that index comes up empty. Could this be due to using an older universal forwarder version? Is there a different way to assign an index?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

This thread is over a year old with an accepted solution so the better way to get a response is to post a new question.

The old version s of Universal Forwarder support index names in inputs.conf exactly the same as newer versions.  The index must exist on the indexers, of course, and you must have access to it.

---
If this reply helps you, Karma would be appreciated.

rosez2
Engager

I have the index in both the inputs.conf stanza, and I also added it to the Splunk Enterprise list of indexes. I don't understand why it worked on my Windows 10 Enterprise and my Kali Linux machines (for Kali I configured through command line), but not Windows 10 2015. I am sure that my steps for Windows 10 2015 and Windows 10 Enterprise are the exact same.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

There might be several things wrong, not the destination index configuration. As @richgalloway already said - please create a new thread describing your configuration and problem. The problem in this thread has already been resolved. Let's keep the Answers nice and tidy 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...