Hello Community,
I wondering that i forward the logs using syslog instead of TCP, I received the packets using TcpDump and everything is good but the data not showing there and it's transferred using tcpdump....
that's my configuration in HF
Outputs.conf
[syslog]
defaultGroup = group2
[syslog:remote_siem]
server = xx.xx.xx.xx:514
sendCookedData = false
transforms.conf
[send_tmds_to_remote_siem]
REGEX = .
SOURCE_KEY = _MetaData:Index
DEST_KEY = _SYSLOG_ROUTING
FORMAT = remote_siem
[send_tmao_to_remote_siem]
REGEX = .
SOURCE_KEY = _MetaData:Index
DEST_KEY = _SYSLOG_ROUTING
FORMAT = remote_siem
props.conf
[source::udp:1518]
TRANSFORMS-send_tmds_to_remote_siem = send_tmds_to_remote_siem
[source::udp:1517]
TRANSFORMS-send_tmao_to_remote_siem = send_tmao_to_remote_siem
is it fine or something not correct please help .