Hi,
How would I route raw data via tcp to an external system (based upon sourcetype or host), but also index that data (and all other data being processed by that splunk forwarder)? I don't see any examples of doing both.
_TCP_ROUTING is not mutually exclusive to indexing.