I got nothing wrong. Step 2 is not possible. Yes, you can change the name of the index, but an event cannot be written to a metric index without conversion. The fact that step 1 works perfectly tells me the data is an event rather than a metric. Splunk has a tendency to overload terms. in this case, "metric" can refer to a numeric value in an event or it can refer to a specific format of data (also numeric) that only a metric index can store. it's the format (or lack of it) that's causing the error message.
... View more