HI,
I'm trying to create a stream for CloudWatch Logs under Splunk Cloud Web, but it is not streaming to the sourcetype/index i have setup. Found out under our Splunk HF, it's already streaming this CW Logs (from S3 directly), but with default configuration (index=aws sourcetype=aws:cloudwatchlogs <resource_id>), It's possible to customize it from the HF ? the "aws_cloudwatch_logs_tasks.conf" is empty.
*OBS: From https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-are-some-AWS-CloudWatch-logs-not-appearing-... , @jzhong_splunk answer, if using HF, i would need to raise ticket, why?