Is it possible to use _TCP_ROUTING with a UDP input? I can not get it to work. My other "monitor" inputs works fine with _TCP_ROUTING. This is a full forwarder not a lwf.
[udp://514] index = testapp sourcetype = syslog _TCP_ROUTING = pnlogGroup
[tcpout] defaultGroup = SlogGroup disabled = false indexAndForward = 0 [tcpout:pnlogGroup] disabled = false server = 10.0.0.41:9997 [tcpout:SlogGroup] disabled = false server = 10.0.0.50:9995
I think you already got answer a looooooong time ago. Answer is yes. A full Forwarder process data and parse events from udp inputs, and send the processed/parsed to Splunk as you configured in outputs.conf.