Dashboards & Visualizations

splunk connect - Send one namespace logs to separate index

New Member

I would want to send logs from one namespace to a separate index where all other logs are send out to one index. I am using  splunk-connect HEC to forward that from the openshift cluster. Can anyone guide how it can be done?

I tried indexRouting=true and adding a local splunk in values file of helm chart. But, i observe token stored in env is only for local and the global value seems to give an error   --> "text":"Incorrect index","code":7,"invalid-event-number":1} "

Labels (3)
0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!