I am a splunk cloud customer with an onprem heavy forwarder.
I have an app on the heavy forwarder which I want to configure for a new INDEX.
Let me know if I am missing anything:
I go into the heavy forwarder and create a new INDEX. Let's say it's called "office"
Then I go into splunk cloud and create the index with the exact same name "office"
Is that all I need to do?
That's it!