Deployment Architecture

Send log in another index based on a tag

lmilcent
New Member

Hello,

I am using docker and I send all containers logs using logspout into a TCP input on Splunk.
Before trying to use Splunk, I was using Graylog. It was possible to extract logs from an input to send it into a specific index, based on a tag.

This is what I am trying to do with Splunk : all logs from all my containers are send in only one input and in consequence into only one index.
Is there a way to apply the same thing that I was doing using Graylog, using the web GUI mostly?

The main goal is to aggregate all logs from one container only into one dedicated index.

Thanks for your help.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...