We have a need to have all log data coming into an index copied off to another logging system. The index is being fed log data through an HEC endpoint directly into our indexer cluster.
Is there a "native" way to do it? Would it scale well?
My only solution right now is an API call every few minutes to grab raw events from the last X minutes. Which seems, uh, not elegant. Is there a better way?
See the docs.
what is the other logging system? Syslog?
Syslog is an option, yes