I have been trying to figure this out for a few days, and I am not getting anywhere.
I have specific data coming in on one server/directory that has a UF installed on it that I want to send to a specific Indexer/Index. Windows logs go to the index cluster, and the PII data needs to go to a stand alone indexer.
So, here is what I have currently,
**** OUTPUTS.CONF ****
defaultGroup = ihf_cluster
server = 10.10.10.1:9997, 10.10.10.2:9997,10.10.10.3:9997,10.10.10.4:9997
server = 10.10.10.100:9997
The monitoring stanza is missing one slash /. Is it a typo OR actual entry that you've?
Please ensure that you configurations matches the example given in below link and you've restarted Splunk UF after making these changes.