I want to add custom fields to specific index and have them log accordingly.
Currently there are only a few default fields such as "host", "index", "sourcetype", etc...
Not sure if this is the best place to add additional data or not.
How can I add more fields?
There is a ton of documentation on this. Start here:
https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/ExtractfieldsinteractivelywithIFX