I am far from being an advanced user of splunk and as a result have a question that I would imagine would be quite simple. What we have used Splunk for up to now, is to dump some of our HP Blade components logs into a syslog server so that we can generate alerts if something happens.
Now, I have other logs that I would like to send into splunk, however I want to separate my HP component logs from these new logs. Is this possible?
I would also like to grant access to a specific group of users to see these new logs....but I don't want them to see anything else (The HP Blade logs).
Thanks!
... View more