Changing the Default Index per-Host


Is it possible to somehow configure the "default" index on a per-host basis? We have several lightweight forwarders and are having to go in and manually edit the index to point to a custom index for each input. Surely there's a way to do it once and have it work everywhere?

Re: Changing the Default Index per-Host

Splunk Employee
Splunk Employee

Yes. You can just add

index = newindex

to the top of inputs.conf (probably $SPLUNK_HOME/etc/system/local/inputs.conf, but any one should work)