Unfortunately, the "filtering" is applied to a particular input (there is no filtering capability as such on Universal Forwarder - the black/whitelisting is a functionality of this particular input). So you can't get two different data streams from a single input. And most of the metadata is specified also at the input level (no advanced manipulation on UF, so no props/transforms) so the most you can do - as others already pointed out is to route the events to two destinations. It's the destination HF/indexer that you can try to manipulate the metadata on further (i.e. rewrite the index, source, sourcetype and so on).
... View more