- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How can I send events from a monitor input file to an index I created?
Rocky31
Path Finder
08-10-2017
10:24 AM
I am not sure about this, it's very tricky. Can anyone help me on this?
Do I need to update any .conf files?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
![skoelpin skoelpin](https://community.splunk.com/legacyfs/online/avatars/284640.jpg)
skoelpin
![SplunkTrust SplunkTrust](/html/@E48BE65924041B382F8C3220FF058B38/rank_icons/splunk-trust-16.png)
SplunkTrust
08-10-2017
10:36 AM
Do you have a fresh install of Splunk? If so, you need to enable your Indexer to listen on port 9997
. Once that's done you then need to use your deployment server (or login to the machine with the forwarder installed) and edit the inputs.conf
to monitor a file and have an outputs.conf
to tell the forwarder where to send the data to
https://docs.splunk.com/Documentation/SplunkCloud/6.6.1/Forwarding/Enableareceiver
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
![adonio adonio](https://community.splunk.com/legacyfs/online/avatars/297047.jpg)
adonio
Ultra Champion
08-10-2017
10:30 AM
identify the index under the monitoring stanza in inputs.conf
[monitor:///my_stuff]
index = my_stuuf_index
![](/skins/images/5D2DD17C284106BFBF80528D01D8AA1A/responsive_peak/images/icon_anonymous_message.png)