Getting Data In

Is any index creation (though cli) is required to configure/onboard new API in to heavy forwarder?

NDabhi21
Explorer

Dear All,

Can you please suggest whether any index creation (though cli) is required to configure/Onboard new API in to Heavy forwarder .

 

APP Name :Cisco Umbrella Add-On for Splunk

 

Labels (1)
Tags (1)
0 Karma

tej57
Builder

Hey @NDabhi21,

If you're onboarding/ingesting data via any methods (REST API, scripted inputs, monitor inputs, etc), you'll need one destination where the data should get ingested in the form of index. If the question was requirement of new index for every new input, then that is not mandatory. You can group the types of inputs and have the logs ingested in one index. However for better accessibility, I would prefer having different index for different types of onboarding.

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...