Hi All,
Let's say I receive log data through TCP on UF, and I want to save the data in event index and metric index as well.
I create new source type and new metric index in order to save the data into metric.
on UF:
inputs.conf
[monitor://xxxxx.log]
index = event_idx
sourcetype = eventsourcetype
on IDX
inputs.conf
[splunktcp://9997]