I'm trying to change were universal forwarders information gets indexed.
Universal forwarder configured to send data to splunkserver:2222
On the Splunk server in my /etc/system/local/inputs.conf I have:
index = notmain
However all the forwarded data goes into the main index.
Adding index=notmain on the universal forwarder /etc/system/local/inputs.conf did the trick