Hi,
We need to send some security events to an external party. We also need this for our internal use.
On my test instance I've configured outputs.conf as
[tcpout]
defaultGroup = security
indexAndForward = 1
[tcpout:security]
server = localhost:9999
Which has got my events flowing to my fake external server and leaves them accessible in the internal side. However I only want to send 2 source types there. How do i filter out the rest of the events?
Hi @pjcable,
as yu can read at https://docs.splunk.com/Documentation/Splunk/9.1.1/Forwarding/Routeandfilterdatad#Replicate_a_subset...
to add a stanza in outputs.conf isn't enough, follow the configuration at the above link.
Ciao.
Giuseppe