Hi there,
I have dozens of devices forwarding data through universal forwarder to a heavy forwarder, which in turn forwards data to a group of indexers.
Due to access provisioning demands, I would like data from each set of these devices to be indexed under a specific index, so users can be granted access to the specific indexes.
By specifying in props.conf and inputs.conf on the heavy forwarder, is it possible to achieve this result?
Any help would be much appreciated.
Splunk newbie.
... View more