Scenario
I have been following - http://docs.splunk.com/Documentation/Splunk/7.0.2/Forwarding/Routeandfilterdatad
And have the following config files.
Inputs.conf
[default] 
host = xxx-xxx-xxx 
[WinEventLog://ForwardedEvents] 
disabled = 0
Props.conf
[WinEventLog:ForwardedEvents] 
TRANSFORMS-routing = routeAll, routeSubset 
Transforms.conf
[routeAll] 
REGEX=(.) 
DEST_KEY=_TCP_ROUTING 
FORMAT=3rdpartyappliance
[routeSubset] 
REGEX=(Avecto) 
DEST_KEY=_TCP_ROUTING 
FORMAT=indexers,3rdpartyappliance 
Outputs.conf
[tcpout] 
defaultGroup = nothing 
[tcpout:3rdpartyappliance] 
server = xxx.xxx.xxx.xxx
# sets the output to raw format. 
sendCookedData = false 
#### Outputs to Splunk Indexer #### 
[tcpout:indexers] 
server = xxx.xxx.xxx.xxx
Results
If I remove defaultGroup=nothing from outputs.conf. Any event is duplicated to the internal and external indexer, but I feel I don't have the right REGEX for only the events that I want to send internally.
 
					
				
		
 
					
				
		
try this,
REGEX=(.+(?i)Avecto.+)
This works! 🙂 Thanks for your help 🙂
 
					
				
		
@raybowden, glad @splunker12er's answer resolved the issue you were having. I've converted his comment as an answer, so if there are not further question in the same topic, please close this question by accepting this answer.
