Hi all, I've setup am SC4S just to forward nix:syslog events. In local/context/splunk_metadata.csv: nix_syslog,index,the_index nix_syslog,sourcetype,nix:syslog Cant find the events inSplunk and splunkd.log is filling with: 12-29-2023 09:52:50.993 +0000 ERROR HttpInputDataHandler [2140 HttpDedicatedIoThread-0] - Failed processing http input, token name=the_token, channel=n/a, source_IP=172.18.0.1, reply=7, events_processed=1, http_input_body_size=1091, parsing_err="Incorrect index, index='main'" The HEC probes at sc4s boot are successful and inserted in the correct index. Any help would be really appreciated. Thank you Daniel
... View more