Hi Team,
We need to drop _internal logs forwarded by universal forwarders as _internal logs are consuming most of the disk space. As the number of universal forwarders is high, it's not possible to change configs on the universal forwarder. Could you please advise on how can we stop indexing _internal received from universal forwarders? How can we drop them on heavy weight forwarder? We just want to enable _internal logs indexing for the heavy weight forwarder but not for Universal forwarders. Please advise.
Our Log flow:
Universal forwarder ---> Heavy weight forwarder --->Indexer
↧