My 2 cents here are: don't do it! Creating 2 or more output groups with one or more 3rd party devices as receivers will only lead to problems. Every time the connection to the syslog server goes down or is too slow or if the syslog server is not responsive, all forwarding stops, also for all the other outputs ... If they really want to do it, you should do it with 2 separate HFW, so as not to cause interference. An HFW that sends data to Splunk and another parallel that sends to 3rd party devices! My "2 millions" "pre-sales" question: WHY would you want a customer to use Splunk set-up to send data to third party tools and being this "POC" scope, sending to third party tools? 🤔 Thanks
... View more