Splunk Enterprise

Unable to send data to multiple indexes using raw endpoint in Splunk HEC

ramganeshn
Explorer

We are trying to send data to raw endpoint via Splunk HEC. When we do so, the data is always sent only to the default index and is not sent to the other indexes. Can someone guide us on how to have this resolved? Any idea? The scenario is as below:

[http://LGS-HEC-PROD]
disabled = 0
index = index_one
indexes = index_one,index_two,index_three,index_four,index_five
token = <OUR_HEC_TOKEN>

We are trying to send data from splunk-library-javalogging and to the raw endpoint of our Splunk HEC. So, whenever we send changing the index from index_one to index_two or index_three, the events are still written to the index_one(Which is the default index index = index_one). This is not happening with the event endpoint and happens only with the raw endpoint. Is this a limitation with the Splunk HEC or are we missing something on this. Please advise.

lbruhns
Explorer

info on this seems sparse i have a similar challenge with k8s coing over hec, i'd like to be able to have more htan one index per token but how does it route?

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...