As my wrestle with configuring Splunk continues, I discovered the following helpful article explaining what happens where when forwarding data to a Splunk server.
Basically, it depends. Which is not surprising, given how complicated Splunk is, but it’s good to have on hand!
Combined with details on configuring linebreaking for multi-line events, perhaps I can get my rails logs handled as one entity in the near future…