For anyone else running into this... you don't need to change indexes on all inputs for all forwards. You can keep working with what you already have. All of these dashboards are fed via macros, which reference other macros. Ultimately, they all reference the os_index macro, which is literally just a "index = os" definition. Change that, via the web config or in .../etc/apps/splunk_app_for_nix/local/macros.conf then reboot Splunk and you're set.
... View more