Hi,
it is possible to configure HWF just to receive and forward syslog without indexing data?
If i do configuration like this and HWF is not configured to forward data into Indexers splunk, HWF splunk instance start indexing data and use data license.
Sebastian
inputs.conf
[default]
host = splunkfwd
[udp://192.168.130.100:2514]
_SYSLOG_ROUTING = syslog-data
outputs.conf
[syslog]
defaultGroup = syslog-data
[syslog:syslog-data]
server = 192.168.130.200:514
type = udp
I don't want to send data to indexer, i just want forward syslog message to another splunk due to firewall limitation i cannot use TCP connection.
Yes this is doable, set up forwarding on your HF.
/en-US/manager/wx/forwardreceive
and all data will go to your indexer. This can also be set via a splunk cmd as well.