splunk_hec sink does not index fields by default
This gives you full control over which fields are indexed
There is no longer a distinction within Vector between explicit and implicit
event fields. All fields are now implicit and therefore the
will not index any fields by default.
In order to mark desired fields as indexed you can use the optional
[sinks.my_sink_id] type = "splunk_hec" inputs = ["my-source-id"] + indexed_fields = ["foo", "bar"]