Hi @KJ10 , could you share your inputs.conf file? anyway, in general, the option index=<your_index> in inputs.conf, if the index is really existent, shouldn't have any issue. Didi you checked if the index is really existent and if you gave the correct grants to it? Anyway, if you restore the original index name in inputs.conf, and restart Splunk on the Forwarder, logs should arrive to the original index; did you restarted the UF after restored the original index? Are you using a Deployment Server to deploy configurations on UF or did you manually modified them? Ciao. Giuseppe
... View more