<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: sc4s index re-route in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/sc4s-index-re-route/m-p/745781#M118533</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;, it is in /opt/sc4s/local/context folder.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 08 May 2025 13:26:18 GMT</pubDate>
    <dc:creator>capjacksparo</dc:creator>
    <dc:date>2025-05-08T13:26:18Z</dc:date>
    <item>
      <title>sc4s index re-route</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/sc4s-index-re-route/m-p/744534#M118310</link>
      <description>&lt;P&gt;Hi Folks,&lt;BR /&gt;&lt;BR /&gt;New to Splunk and SC4S deploymenet. So far I have been able to make good progress. I have setup 2 SC4S servers one on linux and the other on windows with WSL. The challenge that I am facing is that all the syslogs are doing to the default indices. For example I see that the FW logs are going to netfw.&lt;/P&gt;&lt;P&gt;I am trying to move them to a new index that I have created- index_new.&lt;/P&gt;&lt;P&gt;I have tried editing the splunk_metadata.csv file but I still see the logs going to netfw. i have tried different configurations but nothing worked.&amp;nbsp;&lt;/P&gt;&lt;P&gt;fortinet_fortigate,index, index_new&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;ftnt_fortigate, index,index_new&lt;/P&gt;&lt;P&gt;or&amp;nbsp;&lt;/P&gt;&lt;P&gt;netfw,index,index_new&lt;/P&gt;&lt;P&gt;In the HEC configuration, I have not selected any index and left it blank. The default index is set to index_new&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;BR /&gt;&lt;BR /&gt;PS: I have also tried the&amp;nbsp;&lt;SPAN&gt;Maciek Stopa's posfilter.conf script as well.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Apr 2025 16:54:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/sc4s-index-re-route/m-p/744534#M118310</guid>
      <dc:creator>capjacksparo</dc:creator>
      <dc:date>2025-04-20T16:54:50Z</dc:date>
    </item>
    <item>
      <title>Re: sc4s index re-route</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/sc4s-index-re-route/m-p/744536#M118311</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;To re-route logs to a different index in SC4S, you must correctly map the source type to your target index in the splunk_metadata.csv file. The format is:&lt;/P&gt;&lt;PRE&gt;key,index,value&lt;/PRE&gt;&lt;P&gt;Regarding the key names, you can see these at&amp;nbsp;&lt;A href="https://splunk.github.io/splunk-connect-for-syslog/1.91.5/sources/Fortinet/" target="_blank" rel="noopener"&gt;https://splunk.github.io/splunk-connect-for-syslog/1.91.5/sources/Fortinet/&lt;/A&gt;&amp;nbsp;which are:&lt;/P&gt;&lt;P&gt;key sourcetype default index&lt;/P&gt;&lt;TABLE width="340px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="231.445px"&gt;key&lt;/TD&gt;&lt;TD width="107.555px"&gt;default index&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="231.445px"&gt;fortinet_fortios_traffic&lt;/TD&gt;&lt;TD width="107.555px"&gt;netfw&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="231.445px"&gt;fortinet_fortios_utm&lt;/TD&gt;&lt;TD width="107.555px"&gt;netfw&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="231.445px"&gt;fortinet_fortios_event&lt;/TD&gt;&lt;TD width="107.555px"&gt;netops&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="231.445px"&gt;fortinet_fortios_log&lt;/TD&gt;&lt;TD width="107.555px"&gt;netops&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See below for more detail on the&amp;nbsp;splunk_metadata.csv format:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;The columns in this file are key, metadata, and value. To make a change using the override file, consult the example file (or the source documentation) for the proper key and modify and add rows in the table, specifying one or more of the following metadata/value pairs for a given key:

key which refers to the vendor and product name of the data source, using the vendor_product convention. For overrides, these keys are listed in the example file. For new custom sources, be sure to choose a key that accurately reflects the vendor and product being configured and that matches the log path.
index to specify an alternate value for index.&lt;/LI-CODE&gt;&lt;P&gt;&lt;A href="https://splunk.github.io/splunk-connect-for-syslog/main/configuration/#:~:text=The%20columns%20in,value%20for%20index." target="_self"&gt;Check the docs for more info on the format&lt;/A&gt;&lt;/P&gt;&lt;P&gt;After editing splunk_metadata.csv, you &lt;STRONG&gt;must restart the SC4S container or service&lt;/STRONG&gt; for changes to take effect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt; If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sun, 20 Apr 2025 09:22:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/sc4s-index-re-route/m-p/744536#M118311</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-04-20T09:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: sc4s index re-route</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/sc4s-index-re-route/m-p/744538#M118312</link>
      <description>&lt;P&gt;x&lt;/P&gt;</description>
      <pubDate>Sun, 20 Apr 2025 22:29:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/sc4s-index-re-route/m-p/744538#M118312</guid>
      <dc:creator>capjacksparo</dc:creator>
      <dc:date>2025-04-20T22:29:44Z</dc:date>
    </item>
    <item>
      <title>Re: sc4s index re-route</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/sc4s-index-re-route/m-p/744539#M118313</link>
      <description>&lt;P&gt;Thank you &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;i edited the&amp;nbsp;&lt;SPAN&gt;splunk_metadata.csv and removed the existing entires and added the below key,index,value&amp;nbsp; and restarted the SC4S :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;fortinet_fortios_traffic, index, index_new&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;fortinet_fortios_utm, index, index_new&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;That did not work either.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Am i still missing something here ? Also is there a way to change all (netfw,netops,oswin,osnix and so on) the default index to a new single index ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Apr 2025 22:31:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/sc4s-index-re-route/m-p/744539#M118313</guid>
      <dc:creator>capjacksparo</dc:creator>
      <dc:date>2025-04-20T22:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: sc4s index re-route</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/sc4s-index-re-route/m-p/744586#M118329</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/309451"&gt;@capjacksparo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please can you confirm where the&amp;nbsp;&lt;SPAN&gt;splunk_metadata.csv&amp;nbsp; is that you updated?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Im not sure its possible to overwrite the defaults - other than by using the&amp;nbsp;splunk_metadata.csv&amp;nbsp;file.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 15:25:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/sc4s-index-re-route/m-p/744586#M118329</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-04-21T15:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: sc4s index re-route</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/sc4s-index-re-route/m-p/745781#M118533</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;, it is in /opt/sc4s/local/context folder.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2025 13:26:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/sc4s-index-re-route/m-p/745781#M118533</guid>
      <dc:creator>capjacksparo</dc:creator>
      <dc:date>2025-05-08T13:26:18Z</dc:date>
    </item>
  </channel>
</rss>

