Hi @winter4 , a question: do you want to forward data to an Indexer ot to an external system via syslog? I suppose that you are meaning that you want to forward logs, that you are receiving from UF...
See more...
Hi @winter4 , a question: do you want to forward data to an Indexer ot to an external system via syslog? I suppose that you are meaning that you want to forward logs, that you are receiving from UFs or syslogs or HEC, using a HF, maintaining the original host source and sourcetype. What's your issue? if you're sending to an Indexer, you have to use outputs.conf and source, host and sourcetype, by default aren't overwritten and usually remain the original ones, unless you configure overwritting. If instead your have to send to a third party it's different. Ciao. Giuseppe