Deployment Architecture

invalid/deleted index

Splunk_U
Path Finder

I want that Unix TA will send data to index abc instead of index os. So i have changed the outputs.conf file pressent as local with the index name as abc. Now all the data are going to index abc. But i am getting an error that invalid/deleted index=os....
can you please help me out?

Tags (2)

piebob
Splunk Employee
Splunk Employee

where are you seeing the errors? are you running the UNIX app as well on your search head? you're probably seeing other artifacts (like maybe saved searches that power dashboards) that are part of the UNIX app and that also expect the original index name. you might want to just grep $splunk_home/etc/apps/ for the index name.

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...