Can I forward data from the universal forwarders using an intermediate heavy weight forwarder to a third-party system without indexing?
If so, how exactly would I achieve this?
Thanks 🙂
Also, if only specific data coming from the universal forwarder needs to be routed, how to do that?
There are docs about Forwarding data to third-party systems in the Splunk Enterprise Forwarding Data manual, have you looked at those already?