Hi everybody,
I would like to duplicate data coming from my sourcetype in such a way:
- send the original data to Splunk for indexing.
- send the duplicated events to an external server with "<DNS>" prefix string.
How should I modify the transform.conf file in order to do that?
Another question: is there a better way to forwards logs to external server while keeping the original source host (source IP) instead of adding prefixes like what I'm trying to do.
Thanks in advance,
Angelo