Multiple Splunk streaming configs per single Pega Cloud environment

Hello,

For Pega Cloud logs streaming to Splunk (Streaming Pega logs to Splunk) - is it possible to have more than one streaming configurations per single Pega Cloud env?

The use case is that we need to split the logs into two groups, splitting log file types. For example, security logs into one Splunk index, operational into the other one. On Splunk, this would need two different HEC API tokens, which means we need to register two different tokens with Pega Cloud, each with it’s own set of filters by file types.

Is this possible?

I got an answer as part of a support request CC-A4707 that this is not supported. A single Pega Cloud environment can only have a single Splunk streaming configuration at a time.

We’ll be looking into a solution on Splunk side to separate data after initial ingestion