Getting Data In

Do forwarders require indexes.conf?

jaoui
Path Finder

If i am setting up a heavy forwarder to monitor directories and tag indexes, do i need to create an indexes.conf on it or is specifying an index in inputs.conf sufficient?

Tags (1)
0 Karma

yannK
Splunk Employee
Splunk Employee

It shouldn't be necessary.
you can have an heavy forwarder specifying index destinations based on props/transforms or in the inputs, but those indexes only exists on the indexers.

However, if you are using the CLI to specify a new input with a specific index, you may see an error about index missing. This is a bug and will be fixed, this is why it's better to use the configurations files.

Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...