Getting Data In

Change Universal Forwarder index

hgclowns
Engager

I'm trying to change were universal forwarders information gets indexed.

Example:

Universal forwarder configured to send data to splunkserver:2222

On the Splunk server in my /etc/system/local/inputs.conf I have:

[splunktcp://2222]
index = notmain

However all the forwarded data goes into the main index.
Thanks

Tags (2)
0 Karma

hgclowns
Engager

Adding index=notmain on the universal forwarder /etc/system/local/inputs.conf did the trick

Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...