Skip to content

Feature request: Multiple splunk index for multiple event types #120

@arunava-basu

Description

@arunava-basu

Hello Splunk Team,

Good evening.

We have recently used the “Splunk Nozzle for PCF” tile in one of our PCF environments.

In this current tile, we don’t have an option to use multiple splunk indexes for multiple event types.
For example, one index for ‘LogMessage’, one for ‘ValueMetric’ and so on and so forth.

Reason for this requirement:
If we see a huge amount of Application logs that are flowing towards Splunk, then we have to stop that single index which we have configured inside the PCF Ops Manager GUI.
We need to do this as we have some storage restrictions from Splunk’s end.
And after that, we won’t be able to see any other system/component logs inside Splunk GUI as there was only 1 index and we have already stopped that index.

Possible Solution:
If we can use multiple indexes for multiple event types instead of using one index for all the event types. Then we will have the flexibility to start/stop any particular nozzle/index.

We have sent exactly the same request to [email protected]. And they have replied with the following.

I got word back that the Pivotal Ecosystem team brought up your issue with their peers at Splunk today. So the topic is officially part of the discussion. They recommended that you follow that up by filing an issue directly with Splunk so that it is tracked in the partner channel and in Splunk's official system as well.

Please let us know if you already have a solution on this requirement.

Regards,
Arunava Basu

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions