I would want to send logs from one namespace to a separate index where all other logs are send out to one index. I am using splunk-connect HEC to forward that from the openshift cluster. Can anyone guide how it can be done?
I tried indexRouting=true and adding a local splunk in values file of helm chart. But, i observe token stored in env is only for local and the global value seems to give an error --> "text":"Incorrect index","code":7,"invalid-event-number":1} "