I have configured connection between the heavy forwarder and indexer. Also I created a custom index on the indexer.
When I configure HEC on the heavy forwarder, I suppose to be able to select index created on the indexer. However, I cannot select the custom index from the heavy forwarder.
Would there be any suggestions on properly forwarding HEC logs from heavy forwarder to indexer? Thank you.
Hi @kristen,
yes it's correct, from the GUi of an heavy Forwarder isn't possible to address a remote index.
You have two solutions:
I hint to add this problem to Splunk Ideas (ideas.splunk.com).
Ciao.
Giuseppe