In Splunk Connect for Kubernetes Configuration, there is a parameter called "indexRouting".
splunk:
hec:
indexRouting: true
When "indexRouting" is set to "true", Splunk Connect sends the logs of a Kubernetes namespace to an index wich has the identical name as the namespace.
We only want to send the logs of specific namespaces to Splunk. So my question ist: Does Splunk Connect check if a corresponding index exists, before it sends all the logs of a namespace to Splunk?
In Splunk, only the logs of namespaces with a corresponding index are stored. So it makes no sense, to send the logs of namespaces, for which no corresponding index exists, to Splunk (over the network).
... View more