I have a Universal Forwarder (UF) that I'd like to send out both compressed and uncompressed data streams to a single indexer. Would this outputs.conf work:
defaultGroup = index_cluster, index_cluster2
Also, how would I specify which files/data streams should go out to targetGroup indexcluster and which ones should go out to indexcluster2?
Yes, they will work this way.
This is saying by default, send to both.
If you want to specify a target specific to an input use TCPROUTING=name of tcpout on you inputs.conf stanza(s)
View solution in original post