Quantcast
Channel: Questions in topic: "heavy-forwarder"
Viewing all articles
Browse latest Browse all 727

How create an event filter to send an original event to the indexers and a modified event to a syslog server?

$
0
0
We are trying to filter and modify events and have both original and modified event. The original event would go to the indexers and the modified event needs to go to the syslog server. When we used UF -> HF -> Indexer & Syslog, we are unable to retain the original event. Hence, we have introduced another HF for further filtering and event modification. However, the second HF is not processing events. Is this correct approach? Please help. UF -> HF -> Filter for Security events and send it to 2 destinations 1. HF -> Filter and modify data -> Send to syslog 2. Indexer

Viewing all articles
Browse latest Browse all 727

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>