in our system we have same universal forwarders, one indexer and a third-party system that expect only events in syslog-format.
How can I send selected events from the indexer via syslog to my third-party system. That selected events should not save in the indexer. All other events should be indexed.
Is there a way to do this?
I try this configuration, but the index sent all events via syslog.
SYSLOGROUTING = syslog_test
server = 192.168.0.42:10514
Thanks for your help,
with best greetings
you can do that with a transformation.
You define the output in your outputs.conf. Then you create a transformation using props.conf and transforms.conf:
[sourcetypename OR host::HOSTNAME OR source::SOURCENAME]
TRANSFORMS-syslog = syslog_out
REGEX = REGEXTOFILTEREVENTSGOESHERE
It works! Thanks a lot.
But there is one open querstion:
The indexer should not index the events wich go out via syslog. Is this posible?