For some reason I can change the index which Splunk addon for Microsoft IIS sends data. After I added the index line, it still sends to main: [monitor://C:\inetpub\logs\LogFiles\] disabled = 0 sourcetype = ms:iis:default index = iis_logs Changed index to iis_logs, but still sending to main.
... View more