Is there a way to forward logs from Splunk to a 3rd Party collector by Index / SourceType?
Yes you can forward data to 3rd party server based on host,source and sourcetype. Have a look at https://docs.splunk.com/Documentation/Splunk/7.2.6/Forwarding/Forwarddatatothird-partysystemsd
View solution in original post
Hi @jcolon68 ,
Did you have a chance to check out any answers? If any work, please resolve this post by approving it! If your problem is still not solved, keep us updated so that someone else can help you.
Thanks for posting!