I have configured S3 bucket logs with input Generic S3 on splunk heavyforwarder through splunk add-on for AWS and given the index name,but all s3 bucket logs are going to splunk default index _internal. Can someone tell me why all S3 logs are going to my splunk default index _internal. I have checked my given index storage capacity and its not full.
↧