Getting Data In

Stash data going to main index

Bentash
Explorer

anyone knows why stash sourcetype for a particular app(demisto in this case) going to index=main?
i believe these are notables. I will like to know which .conf file contains this setting and how to change from main index to another index.

Thanks
Ben

0 Karma

sandeepmakkena
Contributor

Check your inputs.conf file and see what index is specified init. I think by default it will have index=main, update it to index=YourIndexName and restart the service.

0 Karma

Bentash
Explorer

Thanks Sandeep but there is nothing in inputs.conf

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...