Can the forwarding port be set to a UDP port? Tried changing the type to UDP in the outputs.conf file, but Splunk kept sending it as TCP.
We have a government requirement to forward our logging info to a central log management
location. That group wants us to send our logging info to one of their log relay device.
They want it forwarded to that device on UDP port 514 (Syslog).