Hi,
I have applied NullQ and IndexQ filtering on my log files at Heavy Forwarder. But the client demands, we do not want to throw away the data but also don't want to index it. For sanity testing, is it possible to send the nullQ output to a flat file which will be stored on a per-day basis?
i.e. instead of writing nullqueue in the transforms, can I write name of file or location?
DEST_KEY = queue
FORMAT = nullQueue
Sadly no. There is no "write to file" processor.
Can this be possible:
I route the unwanted data to DEST_KEY=SYSLOG, localhost:541
Then by using SYSLOGNG monitor the 541 port and redirect to a flat file instead of another Splunk instance?
Thanks,
Meenal