Getting Data In

Is it possible to use multiple indexes in a single server?

bwniranjan
New Member

We have a multiple logs in a single server. But, I want to separate those logs to control access. Can we send different log files to different indexes so that we can segrate the logs to users?

Tags (2)
0 Karma

prakash007
Builder

If you have a universal forwarder installed on your host, yes-you can send those logs to different indexes...for instance you can have your inputs configured this way..

inputs.conf
[monitor:///var/log/httpd]
sourcetype = access_common
index = web_access 

[monitor:///var/log/messages]
sourcetype = syslog
index = linux_os
0 Karma

renjith_nair
Legend

@bwniranjan,
Yes of course! You can use multiple indexes in same indexer .

Read though this documentation and let us know in case you have further questions.

How to create multiple indexes
Monitor files and directories with inputs.conf
Input conf for monitor

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...