Hi @gcusello, yes it's distributed on-prem installation. I am not using any add-on for ingesting data. I am using HTTP Event Collector Token to send AWS Cloudwatch logs to Splunk indexers (using load balancing). From the GUI it's possible to select multiple indexes but use only the default index as the log index. So far all the logs are going to the default index and I don't see an option in the HEC settings or GUI where I can change the index name for partial logs coming through the HEC. I tried overriding the index value as you mentioned, but it doesn't work. Any idea what's wrong in the below config? props.conf [source::syslogng:dev/syslogng/*] TRANSFORMS-hecpaloalto = hecpaloalto disabled = false transforms.conf [hecpaloalto] DEST_KEY = _MetaData:Index REGEX = (.*) FORMAT = palo_alto
... View more