I want to route Syslog events to different indexes based on hostname, best to do this on indexer with transforms?
Check this:
https://splunk-connect-for-syslog.readthedocs.io/en/1.9.0/configuration/#override-index-or-metadata-...