All Apps and Add-ons

log is going to _internal index

shashidharh
Explorer

Hi,

Logs are going to _internal index instead of customized index.

host = xxxx
index = _internal
source = C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunkd.log
sourcetype = splunkd

inputs.conf and props.conf are set properly in deployment server.Also verified in the SplunkForwarder "Windows"  server.  Still getting above one , not going to customized index.

What could be the reason ?

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The reason is simple: that is where Splunk is told to put the data.  It's also the default setting so no real surprise.  To find out which config file is specifying the settings, run btool on the forwarder.

\Program Files\Splunk\bin\splunk.exe btool --debug inputs list 

Then you'll know which file to modify to have the data go to the desired index.

Be aware that sending data to a custom index rather than _internal may have license implications and may break some dashboards.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...