I want that Unix TA will send data to index abc instead of index os. So i have changed the outputs.conf file pressent as local with the index name as abc. Now all the data are going to index abc. But i am getting an error that invalid/deleted index=os....
can you please help me out?
where are you seeing the errors? are you running the UNIX app as well on your search head? you're probably seeing other artifacts (like maybe saved searches that power dashboards) that are part of the UNIX app and that also expect the original index name. you might want to just grep $splunk_home/etc/apps/ for the index name.