I have too many machines (almost 500) logging to a single index. I want to create a new index (which I know how to do) and configure some host inputs to write to the new index instead of the old one. All sources are syslog type on UDP 514.
As per the docs:
On the Universal or Heavy forwarder in inputs.conf (depending on the type of input):
[monitor://.../file1.log] _TCP_ROUTING = group1
And then in outputs.conf:
Should work.. Untested. Examples stolen from docs. Let us know if this works...
I have no idea whether the UDP input to TCP routing will work... Really curious to see how this pans out.