Hi,
I am trying to send events in a specific index, regardless of sourcetype, to the Diode Receiver Add-On but cannot really get it to work.
Setting up the add-on using [default] stanza in props.conf matches events in ALL indexes including _internal and that really makes a mess of the main index in the receiver.
I tried using the CEF Add-On but I'm not sure how to configure the routing for cefout. Can it even be configured to send UDP?
This is all done in a test environment without a hardware diode for easy troubleshooting but the goal is to set up two splunk servers separated by a UDP-only-diode and have the main index in both servers contain the same information.
... View more