Getting Data In

Changing the Default Index per-Host


Is it possible to somehow configure the "default" index on a per-host basis? We have several lightweight forwarders and are having to go in and manually edit the index to point to a custom index for each input. Surely there's a way to do it once and have it work everywhere?

Tags (1)

Splunk Employee
Splunk Employee

Yes. You can just add

index = newindex

to the top of inputs.conf (probably $SPLUNK_HOME/etc/system/local/inputs.conf, but any one should work)

Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!