This message originated from Cribl Community Slack.
Click here to view the original link.
If the index of a Syslog source isn't specified in the Fields panel, which index would it go to in Splunk?
Solved
Splunk Syslog Source Index Default Behavior When Not Specified
Best answer by Franco Bonecco
same logic as TCP
Sign up
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
