I am forwarding data from indexer to heavy forwarder How I can append host name in event (_raw) in indxer that will be forwarded to heavy forwarder ?
Can you explain why you are doing this ? What is the heavy forwarder sending to ?
If you want to export data, use a scheduled search to export search results formated as you wish
Can you explain why you are doing this ? What is the heavy forwarder sending to ?
If you want to export data, use a scheduled search to export search results formated as you wish
if the answer suits you, you can accept it.
Here is the method to add any metadata (like host) in the events.
Do that at the indexer level (during index time)
The actual scenario is like this: I am sending data like this...
universalforwarder -> indexer -> Heavy forwarder -> Syslog-ng server
How Can I get Universal forwarder machine address in Syslog-ng server.