You can use method i have implemented with DS distributed bash script automation, which does following with every single HEC input on each server in hfw pool: First, append existing http stanzas in inputs.conf with "fake" output group, like [http://hec_input_1] outputgroup = out01 Define those fake outputs in outputs conf like this: [tcpgroup:out01] server=127.0.0.1:9001 Now we need to set some listener on internal loop input dedicated port that "tags" the data: [splunktcp://9001] _meta = HecName::192.168.0.1:hec_input_1 Repeat all this for for all your hec inputs, make each of it have it's own outputgroup and tcpsplunk port listener, restart splunk and enjoy: |tstats count where index=hec_index by HecName
... View more