IT & IoT Security | Cloud | It's all about the life itself

Nothing in life is as important as you think it is, while you are thinking about it.

Splunk – Define index in inputs.conf


Here is a very simple sample stanza for inputs.conf file.

disabled = 0
index = winevent_app

disabled = 0
index = winevent_sec

disabled = 0
index = winevent_sys

PS. Here in this tutorial the indexes were created on Splunk 7.x before editing the conf file.

As it is seen above , ingestion has started under the respective index as defined in conf file.