ah!
Found something, didnt remember to see that in the documents in:
/opt/splunk/etc/apps/Ansible_Splunk/default/macros.conf there is a
[AnsibleData]
definition = index=main
I changed the main to "myownindex" and it works
... View more
Just on the same problem... see my Ansible-info in my own index, if I search it via "search and reporting" index="myownindex" I see the ansible data. Therefore the ansible-data is inserted. the Ansible Splunk app is empty... I miss a config where to set the index the app is looking into, the Event Collector-Box doesnt show the HEC.
I had a look into the Settings->Indexes and the Index is bound to app Ansibe_Splunk
... View more