Dashboards & Visualizations

How to fix hosts that are reporting default indexes

shreveth
New Member

some hosts are reporting to default indexes rather there respected indexes. So how to fix this issue, please give me code for this as well let me know if there is anything i need to change any configuration file.

0 Karma
1 Solution

woodcock
Esteemed Legend

Every entry in every inputs.conf file should have an index=<SomeValueOtherThanMainHere> line. If you are using a Deployment Server (or other endpoint management tool), this should be easy to check in your main archive.

View solution in original post

0 Karma

woodcock
Esteemed Legend

Every entry in every inputs.conf file should have an index=<SomeValueOtherThanMainHere> line. If you are using a Deployment Server (or other endpoint management tool), this should be easy to check in your main archive.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...