Getting Data In

Stash data going to main index

Bentash
Explorer

anyone knows why stash sourcetype for a particular app(demisto in this case) going to index=main?
i believe these are notables. I will like to know which .conf file contains this setting and how to change from main index to another index.

Thanks
Ben

0 Karma

sandeepmakkena
Contributor

Check your inputs.conf file and see what index is specified init. I think by default it will have index=main, update it to index=YourIndexName and restart the service.

0 Karma

Bentash
Explorer

Thanks Sandeep but there is nothing in inputs.conf

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...