Getting Data In

How to redirect logs from a Universal Forwarder to a specific created index, not the main index?

gopala
New Member

Hi,

I'm trying to redirect all logs from a folder in a forwarder to "just" a specific index that we created on the indexer. This is our own created index and we want to index the logs from that folder on the forwarder "just" in our index, not on the main index.

There is a little confusion here. I have checked some information on the internet and nothing works until now. When somebody says "do something on the inputs.conf" is never clear what to exactly do in that file and "where in that file" (at the beginning?,at the end? in the middle? at random?). It is also never clear to which inputs.conf we should add "this something" because there are several inputs.conf files in different paths. And we even have this file on both the forwarder and the indexer.

Basically, I don't have any clue of "what to add" and "where to add it" (location of the file/files and where within the file).

I have tried several things and nothing works.

Precise and accurate help will be very much appreciated.

Thanks !

0 Karma

jmallorquin
Builder

Hi,

First you have to indetifique where have you configure the inputs (mean in with file inputs.conf is configure your input) you can do this with this command ./splunk cmd btool inputs list --debug

Whe you localize the file inputs.conf in with which you have define the inputs you have to configure in the stanza of the inputs the label "index"

[source or sourcetype]
index = yourindex

Hope help you

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...