I have installed Graylog 2.4.5 in the on-prem server and then I configured & started winlogbeat in that machine and the graylog was started receiving events from the machine and it’s routed to specific stream.
Now I want to send the data to cloud server environment where the same Graylog 2.4.5 is running and I am able to send data from one graylog to another graylog using “Manage Outputs” and under manage output section I have GELF output in which I have given destination host & port details.
I verified in the cloud environment all the data was receiving successfullly but now I want to filter the data in the on-prem before it sending to cloud server.
As an example I want to send only security events data to the cloud server. Is it possible to filter out the data under manage outputs? (I can say elasticsearch query to filter data and then send it to cloud)
Is there any output plugin in Graylog (Manage outputs) which helps to filter data ?
Please let me know your thoughts and it would be very helpful.