outputs.conf
[syslog:syslogGroup]
server = x.x.x.x:514
props.conf
[helloworld]
TRANSFORMS-rsyslog = syslogRouting
transforms.conf
[syslogRouting]
REGEX = .
DEST_KEY = _SYSLOG_ROUTING
FORMAT = syslogGroup
This config is applied on an indexer (many tutorials use a heavy forwarder which by defaults does not index data). This works perfectly in forwarding rawdata in syslog to another system however rawdata is also being indexed. Is there a way to prevent indexing from happening?
I've tried adding a nullQueue stanza to props.conf without luck.
... View more