Hello Splunkers!
I have a question, i have installed a universal forwarder on a AIX server, but all the logs arrives on the index "main", they should be arrive in one especific index that i created. How can i fix this issue and why is this happening?
Check the inputs.conf file(s) on the forwarder to confirm an index is specified for each input.
Check the inputs.conf file(s) on the forwarder to confirm an index is specified for each input.
i have added the next information on the inputs.conf file without any change (informix is the index)
[monitor://$SPLUNK_HOME/audit]
index = informix
Did you restart Splunk after making the change?