Okay, I'm not exactly a new user to Splunk, but I'm new to using a forwarder. In this case, it's a "heavy forwarder". I set the remote hostname as my main Splunk receiver, and configured the receiver to receive on a given port. The problem is that the events from the remote forwarder go into the "main" index. How do I specify an index the forwarded data should go to?
On your forwarder, add index=blah
in to your stanza in inputs.conf:
[monitor:///var/log/foo]
sourcetype=helloworld
index=blah
On your forwarder, add index=blah
in to your stanza in inputs.conf:
[monitor:///var/log/foo]
sourcetype=helloworld
index=blah