Have Palo Alto logs being sent to syslog-ng server. A UF is on the syslog-ng and forwarding logs to Heavy Forwarder. I have a list of specific firewall (hostnames) and zones that I need to filter a copy of the traffic by and send to different (separate) indexer . Is it possible to filter and route using either the UF or HF?
Hi @ezparra05,
You should use HF for route/filter data. Please see below document.
https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad