Getting Data In

winevent index location

a212830
Champion

Hi,

I have a customer who configured a universal forwarder and now wants to send their files to my indexer. I do not want to use "main" as the index, however. I can't find where the index association is for winevent logs. Can someone point me to it?

Tags (1)
0 Karma
1 Solution

dstaulcu
Builder

Inputs.conf

index =

  • Sets the index to store events from this input.

  • Primarily used to specify the index to store events coming in via this

input stanza.

  • Detail: Sets the index key's initial value. The key is used when

selecting an index to store the events.

  • Defaults to "main" (or whatever you have set as your default index).

View solution in original post

0 Karma

dstaulcu
Builder

For future reference, If you run .\bin\splunk.exe cmd bool inputs list --debug on the agent in question it will list input settings in effect and the input.conf instances from which those settings are derived.

0 Karma

dstaulcu
Builder

Inputs.conf

index =

  • Sets the index to store events from this input.

  • Primarily used to specify the index to store events coming in via this

input stanza.

  • Detail: Sets the index key's initial value. The key is used when

selecting an index to store the events.

  • Defaults to "main" (or whatever you have set as your default index).
0 Karma

a212830
Champion

Thanks. I realize the inputs.conf is where the indexer gets identified, I was looking for which inputs.conf is used for windows events. I found it in the MsiCreated directory.

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...