I want to send indexed data to a syslog server.
I created "syslog1", and I want to send this indexed data only to the syslog server.
Problem is, by default, my indexer is sending "main", "syslog1", and all other indexed data to the syslog server (which is unnecessary data).
Is there any option I can send this "syslog1" data only to syslog?
You'll need to create props.conf and transforms.conf for each sourcetype OR source OR host you wish to segregate:
Configure all your inputs (sourcetype OR source OR host ) that are populating the index named syslog1 according to this documentation: