Getting Data In

how to force all data to go to a different index?

matt
Splunk Employee
Splunk Employee

How do I force all data to go to a different index without inserting index=foo for all input stanzas?

Tags (2)
0 Karma
1 Solution

Alan_Bradley
Path Finder

change the default index= under [default]

View solution in original post

Alan_Bradley
Path Finder

change the default index= under [default]

haraksin
Communicator

This doesn't work if you have a different index defined under the [monitor] stanzas... so it won't be forced really

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...