Hi Folks,
we are ingested the aws vpc flow logs in splunk and able to see the data while searching with index but while searching with source it is not showing any data for that particular source.
for example: while using below search it is showing data.
1. index=* and able to see that source(aws:cloudwatch:vpclogs)
2. index=* | stats count by source , it is display the source(aws:cloudwatch:vpclogs) with 86 event counts.
but while searching with below command.
index=* source=aws:cloudwatch:vpclogs it is not displaying any data.
Thanks,
Sridhar