Deployment Architecture

invalid/deleted index

Splunk_U
Path Finder

I want that Unix TA will send data to index abc instead of index os. So i have changed the outputs.conf file pressent as local with the index name as abc. Now all the data are going to index abc. But i am getting an error that invalid/deleted index=os....
can you please help me out?

Tags (2)

piebob
Splunk Employee
Splunk Employee

where are you seeing the errors? are you running the UNIX app as well on your search head? you're probably seeing other artifacts (like maybe saved searches that power dashboards) that are part of the UNIX app and that also expect the original index name. you might want to just grep $splunk_home/etc/apps/ for the index name.

Get Updates on the Splunk Community!

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...