splunk-connect-for-syslog
splunk-connect-for-syslog copied to clipboard
Different metadata values for every destination
SC4S version: 3.31.0
Host OS: Ubuntu 22.04.4 LTS (Jammy Jellyfish)
Runtime: Docker + systemd
I have to send data from my SC4S instance to a different Splunk Cloud deployment altoguether. The index names in this alternate destination differ from the ones I'm currently using. How can I modify the metadata that I send to the alternate destination so that the index names match without disturbing the metadata I send to my own Splunk Cloud deployment?