Hi @90522prakash, the message you have means that in your inputs.conf on those hosts there's an input stanza in inputs.conf that is configured to send logs to Index="A". You can check running from CLI on those forwarders the btool command /opt/splunk/bin/splunk cmd btool inputs list --debug | grep "index" so check if there's an index=A. Ciao. Giuseppe
... View more