Getting Data In

winevent index location

a212830
Champion

Hi,

I have a customer who configured a universal forwarder and now wants to send their files to my indexer. I do not want to use "main" as the index, however. I can't find where the index association is for winevent logs. Can someone point me to it?

Tags (1)
0 Karma
1 Solution

dstaulcu
Builder

Inputs.conf

index =

  • Sets the index to store events from this input.

  • Primarily used to specify the index to store events coming in via this

input stanza.

  • Detail: Sets the index key's initial value. The key is used when

selecting an index to store the events.

  • Defaults to "main" (or whatever you have set as your default index).

View solution in original post

0 Karma

dstaulcu
Builder

For future reference, If you run .\bin\splunk.exe cmd bool inputs list --debug on the agent in question it will list input settings in effect and the input.conf instances from which those settings are derived.

0 Karma

dstaulcu
Builder

Inputs.conf

index =

  • Sets the index to store events from this input.

  • Primarily used to specify the index to store events coming in via this

input stanza.

  • Detail: Sets the index key's initial value. The key is used when

selecting an index to store the events.

  • Defaults to "main" (or whatever you have set as your default index).
0 Karma

a212830
Champion

Thanks. I realize the inputs.conf is where the indexer gets identified, I was looking for which inputs.conf is used for windows events. I found it in the MsiCreated directory.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...