Dashboards & Visualizations

splunk connect - Send one namespace logs to separate index

m_k_90
New Member

I would want to send logs from one namespace to a separate index where all other logs are send out to one index. I am using  splunk-connect HEC to forward that from the openshift cluster. Can anyone guide how it can be done?

I tried indexRouting=true and adding a local splunk in values file of helm chart. But, i observe token stored in env is only for local and the global value seems to give an error   --> "text":"Incorrect index","code":7,"invalid-event-number":1} "

Labels (3)
0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!