Getting Data In

Two diffent indexes

arkonner
Path Finder

Is it possible to send different logs on two different indexes

[default]
host = EDGE1

[script://$SPLUNK_HOME\bin\scripts\splunk-wmi.path]
disabled = 0

[WinEventLog://Microsoft-Windows-WinNat/Oper]
disabled = 0
index = DAlogs
whitelist = 1017,4303,2000,4304,1018

[monitor:///C:\Program Files\log_nlb]
disabled = 0
sourcetype = csv
index = nlb_log

Tags (3)
0 Karma
1 Solution

ddrillic
Ultra Champion

Sure, in the monitor, you specify the exact log path and its corresponding index.

View solution in original post

0 Karma

somesoni2
Revered Legend

Yes, the index name is available for each data input stanza and each input stanza can be configured to a different indexes (index should exist on the indexer)

0 Karma

ddrillic
Ultra Champion

Sure, in the monitor, you specify the exact log path and its corresponding index.

0 Karma

arkonner
Path Finder

The sintax in the inputs.conf reported above is it correct? Can you please add an example

0 Karma
Get Updates on the Splunk Community!

Security Highlights: September 2022 Newsletter

 September 2022 The Splunk App for Fraud Analytics (SFA) is now Splunk SupportedUse your existing Splunk ...

Platform Highlights | September 2022 Newsletter

 September 2022 What’s New in 9.0 and How to UpgradeGet a walk through of what is new Splunk Enterprise 9.0 ...

Observability Highlights | September 2022 Newsletter

 September 2022 Splunk Observability SuiteAccess to "Classic" SignalFx Interface Will be Removed on Sept 30, ...