[syslog:syslogGroup]
server = x.x.x.x:514
[helloworld]
TRANSFORMS-rsyslog = syslogRouting
[syslogRouting]
REGEX = .
DEST_KEY = _SYSLOG_ROUTING
FORMAT = syslogGroup
This config is applied on an indexer (many tutorials use a heavy forwarder which by defaults does not index data). This works perfectly in forwarding rawdata in syslog to another system however rawdata is also being indexed. Is there a way to prevent indexing from happening?
I've tried adding a nullQueue stanza to props.conf without luck.
Is the data already cooked when it hits the indexer? / What's forwarding the data to the indexer?
Data is not not cooked
UF-->This splunk instance (both Indexer and Search Head role)
Set index = false for indexAndForward in outputs.conf.
[indexAndForward]
index=false
This will stop not just [helloworld] but all other indexes from indexing.
The splunk instance itself is an Indexer and a Search Head at the same time.
You can try this. Set selectiveIndexing = true. And remove attribute _INDEX_AND_FORWARD_ROUTING if added under monitor stanza in inputs.conf. This makes forwarder to not index this data.
[indexAndForward]
index=true
selectiveIndexing = true
This stopped indexing on all indexes as well..
I might consider setting up a HF to pick up data from UF instead of sending directly to Indexer.