Good afternoon, Yes, I am most assuredly not on AWS, but running an on-premise solution. This means that I cannot archive off to S3 buckets, which are an AWS thing (for the most part). For your suggested solutions, can you point me towards the relevant documentation or add some additional details that might get me started on the right path? My gut reaction is that option 1 is likely the solution of choice. The Splunk configuration "props + transforms.conf" part has me scratching my head a bit, though I think I got it from the rsyslog part onward. Thanks!
... View more