Splunk – Define index in inputs.conf
Here is a very simple sample stanza for inputs.conf file.
[WinEventLog://Application] disabled = 0 index = winevent_app [WinEventLog://Security] disabled = 0 index = winevent_sec [WinEventLog://System] disabled = 0 index = winevent_sys
PS. Here in this tutorial the indexes were created on Splunk 7.x before editing the conf file.
As it is seen above , ingestion has started under the respective index as defined in conf file.