You need to modify the macros.conf in the Splunk App for Windows Infrastructure 1.5.2, to reflect your custom indexes.
like:
[wineventlog-index]
definition = index=oswin OR index=oswinsec
[perfmon-index]
definition = index=oswinperf
[msad-index]
definition = index=appmsad
[windows-index]
definition = index=oswinscript OR index=netipam OR index=appmsadmon
in /opt/splunk/etc/apps/splunk_app_windows_infrastructure/local
Best Regards.
... View more