Getting Data In

winevent index location

a212830
Champion

Hi,

I have a customer who configured a universal forwarder and now wants to send their files to my indexer. I do not want to use "main" as the index, however. I can't find where the index association is for winevent logs. Can someone point me to it?

Tags (1)
0 Karma
1 Solution

dstaulcu
Builder

Inputs.conf

index =

  • Sets the index to store events from this input.

  • Primarily used to specify the index to store events coming in via this

input stanza.

  • Detail: Sets the index key's initial value. The key is used when

selecting an index to store the events.

  • Defaults to "main" (or whatever you have set as your default index).

View solution in original post

0 Karma

dstaulcu
Builder

For future reference, If you run .\bin\splunk.exe cmd bool inputs list --debug on the agent in question it will list input settings in effect and the input.conf instances from which those settings are derived.

0 Karma

dstaulcu
Builder

Inputs.conf

index =

  • Sets the index to store events from this input.

  • Primarily used to specify the index to store events coming in via this

input stanza.

  • Detail: Sets the index key's initial value. The key is used when

selecting an index to store the events.

  • Defaults to "main" (or whatever you have set as your default index).
0 Karma

a212830
Champion

Thanks. I realize the inputs.conf is where the indexer gets identified, I was looking for which inputs.conf is used for windows events. I found it in the MsiCreated directory.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...