Hello,
I have an index cluster and would like to send ALL data to a non splunk third party end point. is this possible?
this is the props.conf however for an index cluster where should i configure these files?
the second configuration is the transforms.conf
the final configuration is the outputs.conf
[syslog] TRANSFORMS-routing = routeAl
[routeAll] REGEX=(.) DEST_KEY=_TCP_ROUTING FORMAT=Everything
[tcpout] defaultGroup=nothing [tcpout:Everything] disabled=false
sendCookedData=false
server=10.1.12.1:10514
my concern is that i actually just want to forward all of my data. is there a particular configuration needed for this? or any ideas?
many thanks
Willsy