Dashboards & Visualizations

Set a default index for all INPUTS within a specific app only

eden881
Path Finder

I have an app with a long list of inputs. I want to set them to go to a specific index (let's say index = my_index).
I can achieve this by placing index = my_index under the [default] stanza in the app.

However, will this affect other apps on the forwarder with their inputs set to default?
I deploy this app with a Deployment Server to several UFs.

0 Karma
1 Solution

eden881
Path Finder

Eventually I tried it out myself, and found out that the [default] stanza only affects the inputs in it's specific app.

View solution in original post

0 Karma

eden881
Path Finder

Eventually I tried it out myself, and found out that the [default] stanza only affects the inputs in it's specific app.

0 Karma

ccWildcard
Explorer

I tried this on a server and found the opposite to be true. It was setting index across all stanzas at leas the ones set in etc\system\default\inputs.conf for the forwarder.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Settings in .conf files are not app-specific, they are stanza-specific. Values in the [default] stanza apply to all inputs in all apps unless overwritten by the [default] stanza in another app that is processed first. btool can tell you what settings will apply.

---
If this reply helps you, Karma would be appreciated.

eden881
Path Finder

I think this is incorrect, as I tried it and found out that [default] only affects the inputs in the specific app...

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...