Thank you! After reading the link, I am still not clear on the outputing UDP 514 part . If I receive at the IF a TCP steam, can I send out\forward to rsyslog over UDP 514? In summary, can I receive on TCP and send out\forward on UDP 514?
Or, do I also have to receive on UDP as well and change my inputs.conf to receive on udp 514? My current
Inputs.conf on the IF is :
[splunktcp://9997]
disabled = 0
compressed = false
Also, is the only way to forward on UDP 514 is using by using syslog stanza?
... View more