Getting Data In

How can I forward to a specific custom index?

MU_IT
New Member

I would like to aggregate data from my NPS servers for helpdesk/support use. I have set up a custom index on each server, and I can pull up data with searches on each inside these indexes. How would I forward just the data in a custom index to my central splunk server?

I hope to set up a search on my central server for "NPS Login Failures" and the like against index="NPS_LOGS".

I am 100% windows, using 4.1.2 on all systems.

Thanks.

Tags (2)
0 Karma

Mick
Splunk Employee
Splunk Employee

If it's the case that you want to index some data locally and forward other data to another indexer, then you want to route the data using the instructions here.

Alternatively, you can just index the data on your local instance as well as your remote instance, by specifying your custom index in the appropriate index in inputs.conf and then using indexAndForward = true in outputs.conf.

Whatever your requirements are, there will likely be some data-routing work involved if you want to have different data available in different instances.

A much simpler alternative is just put your data into a custom index on your main indexer, and then restrict the relevant users to only having search privileges on that index. You can then provide access locally on that instance, or use a remote instance to distribute searches

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...