Hi SMEs,
We need to split event logs into 2 different indexes (index_1 & index_2) which is coming to index_1 only as of now.
FYI - The log source is on AWS cloud and we are using add-on to get those logs through inputs.
I tried this and it is not working for me
Hi
Here is one example how to do it based on events.
You could define default index on UF's inputs.conf and then route needed events to another index based on above example. There are many other answers about this if needed.
r. Ismo