We are running Graylog 4.1 with Splunk plugin configured as an output. We can forward messages from custom created streams to Splunk (as output); however, messages from “All Events” stream cannot be forwarded.
Is the “All Events” stream special and cannot be used for forwarding alerts through an output?
I did a quick look and created an Output on All Events. Should be good and nothing special. Only thing that would be special is the Output with Enterprise next to it.
We can create an output as well; however, it is not forwarding any alerts. We have installed the Splunk plugin and it can forward messages from any custom streams but not from “All Events” stream.
Moreover, I noticed that if I create a custom stream (clone of All Events) with index set to “Graylog Events” the new stream is not getting any alerts - even with All Events stopped.