Deployment Architecture

I want to send logs to another index that I created, not the main index. How to do it?

sacalao
New Member

I want to send logs to another index that I created, not the main index. How to do it?

I need to configure something on the splunk server too (inputs.conf)?

Thanks!

0 Karma

Dimitri_McKay
Splunk Employee
Splunk Employee

in the UI you'd go Manager > Indexes > and define the new index name.
Then you'd edit your inputs.conf for that source to point to the name of the new index.
That should do you right.

0 Karma

Ayn
Legend

For the input you want to send to another index, simply specify this in the input's section in inputs.conf.

[monitor:///your/file/or/directory]
index = yourindex

http://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf

Ayn
Legend

I'm not sure I understand the question. It doesn't matter if you got the data through a forwarder or not. You set this on the instance that's reading the files, in your case the forwarder. Duplication isn't an issue at all.

sacalao
New Member

Thanks, but I am getting the logs of a fowarder on port 9997. Using this I not'll be duplicating the data?

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...