I have a Universal Forwarder (UF) that I'd like to send out both compressed and uncompressed data streams to a single indexer. Would this outputs.conf work:
defaultGroup = index_cluster, index_cluster2
Also, how would I specify which files/data streams should go out to targetGroup index_cluster and which ones should go out to index_cluster2?
Yes, they will work this way.
This is saying by default, send to both.
If you want to specify a target specific to an input use _TCP_ROUTING=name of tcpout on you inputs.conf stanza(s)
View solution in original post