Hi,
I have a customer who configured a universal forwarder and now wants to send their files to my indexer. I do not want to use "main" as the index, however. I can't find where the index association is for winevent logs. Can someone point me to it?
Inputs.conf
index =
Sets the index to store events from this input.
Primarily used to specify the index to store events coming in via this
input stanza.
selecting an index to store the events.
For future reference, If you run .\bin\splunk.exe cmd bool inputs list --debug on the agent in question it will list input settings in effect and the input.conf instances from which those settings are derived.
Inputs.conf
index =
Sets the index to store events from this input.
Primarily used to specify the index to store events coming in via this
input stanza.
selecting an index to store the events.
Thanks. I realize the inputs.conf is where the indexer gets identified, I was looking for which inputs.conf is used for windows events. I found it in the MsiCreated directory.