Is it possible to change this app to use a custom index? We have a multi-platform shop and I want windows events out of 'main'.
I've tried to change it myself but some things don't work properly and the index seems to be hard-wired here and there.
bringing this answer from sideone over from the app download page:
"I have been able to configure windows app to work properly under an alternate index. I have modified the following files:
/opt/splunk/etc/apps/windows/default/inputs.conf:
Under each stanza, add the following line:
index=NEW_INDEX_NAME
/opt/splunk/etc/apps/windows/default/wmi.conf:
Change all index entries from index = default to index = NEW_INDEX_NAME
Better still:
- Create a "local" directory under /etc/apps/windows/
- Copy inputs.conf and wmi.conf to /etc/apps/windows/local/
- Delete everything under each stanza heading and replace with "index=NEW_INDEX_NAME"
That way your changes aren't overwritten when you next upgrade.
If you need assistance, i usually idle in #splunk on EFnet.
sideone