Getting Data In

Changing the Default Index per-Host


Is it possible to somehow configure the "default" index on a per-host basis? We have several lightweight forwarders and are having to go in and manually edit the index to point to a custom index for each input. Surely there's a way to do it once and have it work everywhere?

Tags (1)

Splunk Employee
Splunk Employee

Yes. You can just add

index = newindex

to the top of inputs.conf (probably $SPLUNK_HOME/etc/system/local/inputs.conf, but any one should work)

.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!