Getting Data In

sinkhole policy

indikaw
Explorer

I would like to use the sinkwhole policy to tell splunk to index a folder.
Please see below. I need to send these lgos to a seperate index. How can I define the index here to be sent? Whats the syntax.
Also if I append the below to the input.conf is it correct? There are some other stanzas in the input.conf already.

In $SPLUNK_HOME/etc/system/local/inputs.conf
[batch://YOURPATHHERE]
move_policy = sinkhole
host=HHHH
followSymlink = false

Tags (1)
0 Karma

lguinn2
Legend

This should do it -

[batch://YOURPATHHERE]
move_policy = sinkhole
host=HHHH
followSymlink = false
index=XXXXXX

Where XXXXXX is the name of the index where you want to send the data

0 Karma

indikaw
Explorer

can you confirm other part of my question. in the input.conf. can i just append this ?

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...