I want to send logs to another index that I created, not the main index. How to do it?
I need to configure something on the splunk server too (inputs.conf)?
Thanks!
in the UI you'd go Manager > Indexes > and define the new index name.
Then you'd edit your inputs.conf for that source to point to the name of the new index.
That should do you right.
For the input you want to send to another index, simply specify this in the input's section in inputs.conf.
[monitor:///your/file/or/directory]
index = yourindex
http://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf
I'm not sure I understand the question. It doesn't matter if you got the data through a forwarder or not. You set this on the instance that's reading the files, in your case the forwarder. Duplication isn't an issue at all.
Thanks, but I am getting the logs of a fowarder on port 9997. Using this I not'll be duplicating the data?