- Product: Splunk Platform
- Feature: Splunk Connect for Syslog Add-on
- Function: Custom indexes
When routing data from SC4S, you may have existing indexes you need to use for compliance or other reasons.
The splunk_metadata.csv is a file that contains a “key” that is referenced in the log path for each data source. These keys are documented in the individual source files in this section, and allow you to override Splunk metadata either in whole or part. To achieve custom index routing, update the contents of splunk_metadata.csv in /opt/sc4s/local/context on the host to:
cisco_asa,index,<custom index name>
Additionally, these Splunk resources might help you understand and implement this use case: