I plan to deploy the Splunk UF across all my Windows client PCs using SCCM. But I'm confused about the index settings. I want to send all the data to a specific index but when the UF installs it just defaults to the main index.
Is there a way to specify the index during installation? As I don't want data going to main before I change it.
Hi @DashZentin
You cannot change the index used for the Windows inputs as part of the installation process, however you could run the MSI with 'LAUNCHSPLUNK=0' and then modify the inputs.conf once the package is installed before then starting the Splunk forwarder service to complete the installation.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing