I'm attempting to set up a windows instance which will act as a forwarder to our main linux indexer.
The layout looks something like this:
windows box #1 windows box #2
^ ^
||
|
windows
forwarder
|
Linux
indexer
I'd like to have all event logs gathered thrown into a specific index, while wmi monitored events go to another on the main indexer.
Is there a way to do this? I know I can do it when using the light forwarder for linux, just not sure how to do it for windows.
Brian
[Revised on Wed, 17 Mar 2010 06:41:07 -0700]
Looks like my little ascii drawing failed to translate after posting.