Hi @gcusello, Thank you for your response, Once the event has been processed by the SC4S (Splunk-connect-for-syslog), it is sent as HTTP so I don't think I'll have a problem with volume. From the documentation, a single SC4S instance with proper hardware requirements can handle up to 6TB/day. The events will be replicated on my heavy forwarder, I did try the method described on https://docs.splunk.com/Documentation/Splunk/8.2.4/Forwarding/Routeandfilterdatad#Replicate_a_subset_of_data_to_a_third-party_system but using this method, I'd have to create an entry in my props.conf for each source / host /sourcetype. This would mean a lot of repetitive / unnecessary work to maintain. It would be much simpler to be able to replicate an entire index to a third party system. Do you know if it is possible ? Best regards, François.
... View more