Getting Data In

How to send data to a custom index which is currently being sent to main index?

amulay26
Path Finder

Am trying to solve a problem here. The inputs.conf for one of the monitoring stanza on the forwarder had index = main . I changed the inputs.conf on Deployment server and defined index = a and enabled restart splunkd. Am able to see an updated inputs.conf with index = a under the monitoring stanza. However, when I do a btool, I still see index = main for the same monitoring stanza.

How do I send data to index = a instead of index = main?

Any help will be appreciated. Thanks.

Tags (1)
0 Karma

pramit46
Contributor

Please check whether or not you are using the correct serverclass. Perhaps the configuration is not even getting pushed into the forwarder. Hence even if you change on the DS, the FWD still shows the older version.

0 Karma

amulay26
Path Finder

The serverclass is correct too.

0 Karma

amulay26
Path Finder

I did a btool as well. There is no alternate inputs.conf on the Forwarder.

0 Karma

Mayurmpatil
Path Finder

Hello @amulay26 - may be there is one more inputs.conf in some other app or system local in your splunk enterprise.
with below command please find it.

/opt/splunk/bin/splunk cmd btool inputs list --debug | grep index

you will get all the inputs.conf files splunk is using in you environment .

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...