Getting Data In

Changing the Default Index per-Host


Is it possible to somehow configure the "default" index on a per-host basis? We have several lightweight forwarders and are having to go in and manually edit the index to point to a custom index for each input. Surely there's a way to do it once and have it work everywhere?

Tags (1)

Splunk Employee
Splunk Employee

Yes. You can just add

index = newindex

to the top of inputs.conf (probably $SPLUNK_HOME/etc/system/local/inputs.conf, but any one should work)

Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.