Hi @venkatasri , Thanks for your response. I was already aware of getting the Intermediate Forwarder Host from the Splunk internal logs using the SPL you have given below but wanted a better option as it was not easy to trouble shoot or track. With respect to the creation of the index time field, I did some further reading and looks like we can only extract index field from the raw data or from one of the Splunk metadata fields (Source Type, Source or Host). In this case are you asking us to do like the below [<sourcetype>] SOURCE_KEY = MetaData:Host REGEX = (.*) FORMAT = intermediate_forwarder::$1 WRITE_META = true
... View more