All,
Just reading -
http://blogs.splunk.com/2016/05/05/high-performance-syslogging-for-splunk-using-syslog-ng-part-1/?awesm=splk.it_x0t
And it's mentioned that we can drop events at the source with the UF? Is this true? and how did I miss this!? is this just normal props.conf/transforms.conf config?
thanks!
↧