Getting Data In

Change the index name of Splunk_CiscoFirewalls

deyeo
Path Finder

instead of storing the cisco firewall logs into "summary" index. i would like to store in a index called "firewall".

other than creating the index "firewall", and adding index = firewall into the local/inputs.conf, what else must i do?

Tags (1)
0 Karma

yannK
Splunk Employee
Splunk Employee

Changing the inputs is a good start.

If some data are generated using summary searches, then you need also to check the destination index of the summary. (default is summary). see in savedsearches.conf

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...