You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
HEC supports passing additional fields that are not directly part of the event data. This is useful for example to provide additional metadata about the events beyond just the sourcename.
Hi @dtregonning
This feature would meet our use case perfectly. We want to be able to specify the Splunk index from within the application logs, and unfortunately there is no simple way of doing this with the current version of the Splunk docker logging driver.
I note this issue has been open for 3 years, I'm surprised there isn't more interest. Do you know if there is a plan to include this at all?
Thanks
HEC supports passing additional fields that are not directly part of the event data. This is useful for example to provide additional metadata about the events beyond just the sourcename.
https://docs.splunk.com/Documentation/Splunk/7.2.1/Data/IFXandHEC
The text was updated successfully, but these errors were encountered: