Getting Data In

How to redirect logs from a Universal Forwarder to a specific created index, not the main index?

gopala
New Member

Hi,

I'm trying to redirect all logs from a folder in a forwarder to "just" a specific index that we created on the indexer. This is our own created index and we want to index the logs from that folder on the forwarder "just" in our index, not on the main index.

There is a little confusion here. I have checked some information on the internet and nothing works until now. When somebody says "do something on the inputs.conf" is never clear what to exactly do in that file and "where in that file" (at the beginning?,at the end? in the middle? at random?). It is also never clear to which inputs.conf we should add "this something" because there are several inputs.conf files in different paths. And we even have this file on both the forwarder and the indexer.

Basically, I don't have any clue of "what to add" and "where to add it" (location of the file/files and where within the file).

I have tried several things and nothing works.

Precise and accurate help will be very much appreciated.

Thanks !

0 Karma

jmallorquin
Builder

Hi,

First you have to indetifique where have you configure the inputs (mean in with file inputs.conf is configure your input) you can do this with this command ./splunk cmd btool inputs list --debug

Whe you localize the file inputs.conf in with which you have define the inputs you have to configure in the stanza of the inputs the label "index"

[source or sourcetype]
index = yourindex

Hope help you

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...