Getting Data In

sinkhole policy

indikaw
Explorer

I would like to use the sinkwhole policy to tell splunk to index a folder.
Please see below. I need to send these lgos to a seperate index. How can I define the index here to be sent? Whats the syntax.
Also if I append the below to the input.conf is it correct? There are some other stanzas in the input.conf already.

In $SPLUNK_HOME/etc/system/local/inputs.conf
[batch://YOURPATHHERE]
move_policy = sinkhole
host=HHHH
followSymlink = false

Tags (1)
0 Karma

lguinn2
Legend

This should do it -

[batch://YOURPATHHERE]
move_policy = sinkhole
host=HHHH
followSymlink = false
index=XXXXXX

Where XXXXXX is the name of the index where you want to send the data

0 Karma

indikaw
Explorer

can you confirm other part of my question. in the input.conf. can i just append this ?

0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...