Skip to main content
Solved

Splunk Syslog Source Index Default Behavior When Not Specified

  • June 23, 2026
  • 4 replies
  • 0 views

This message originated from Cribl Community Slack.
Click here to view the original link.

If the index of a Syslog source isn't specified in the Fields panel, which index would it go to in Splunk?

Best answer by Franco Bonecco

same logic as TCP

4 replies

Splunk TCP dests default to main , while HEC doesn't set one

  • Author
  • Participating Frequently
  • June 23, 2026
What about the Splunk Indexing Load Balancer destination?

same logic as TCP

  • Employee
  • June 23, 2026
You can also check if a "last chance" index is defined in indexes.conf. That defines a fallback destination for events destined for non-existent, disabled, or deleted indexes.