Thank you for the instructions. When I checked we had that already setup outputs.conf like that.
I am currently trying to find out where we went wrong but as I move thru the flow I will find it and post the resolution.
Currently the security appliance acts as a server to the heavy fwder, and we don't need inputs.conf because the appliance sends host, sourcetype, index, time. I think we just mis-configured where we assigned the index to... but still looking
... View more