Deployment Architecture

Send log in another index based on a tag

lmilcent
New Member

Hello,

I am using docker and I send all containers logs using logspout into a TCP input on Splunk.
Before trying to use Splunk, I was using Graylog. It was possible to extract logs from an input to send it into a specific index, based on a tag.

This is what I am trying to do with Splunk : all logs from all my containers are send in only one input and in consequence into only one index.
Is there a way to apply the same thing that I was doing using Graylog, using the web GUI mostly?

The main goal is to aggregate all logs from one container only into one dedicated index.

Thanks for your help.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...