I am using splunk sc4s, I am currently receiving events from a data source that is WAF through the udp port 514 and they are being indexed to the waf index, I want to receive events from another source called DBF and have them indexed to the index called dbf , How can I do that?
Currently I am seeing the events of the WAF and DBF data source at the waf index