Hello Thanks for the reply. I was looking at https://docs.splunk.com/Documentation/Splunk/8.2.6/admin/Inputsconf and under GLOBAL SETTINGS is says: index = <string>
* Sets the index to store events from this input.
* Primarily used to specify the index to store events that come in through
this input stanza.
* Default: main (or whatever you have set as your default index) So I wasn't sure I needed to add anything? Also when I installed the Universal Forwarder on the Windows Server where the Syslog file are, I added a path to the folder to monitor, and this did not add an index tag either? However, I'll give it a try and see if adding the index tag works. Thanks DAS Admin
... View more