Hi, 
 I've installed a Universal Forwarder and it is forwarding Windows events fine to the Splunk server. 
 Hoever, all Windows eventlogs are indexed in the "main" index of Spunk and I would like to have these indexed somwhere else.  
I can't find out what stanza I should use to specify an index for the eventlogs in the config of the Universal forwarder. 
 The idea is to have multiple types of Windows hosts configured to use different indexes, all bering forwarded to the same Splunk server. 
 Best regards, 
						
					
					... View more