# How to forward ALL logs

**URL:** <https://discuss.elastic.co/t/how-to-forward-all-logs/339653>\
**Category:** Logstash\
**Created:** [July 31, 2023, 7:20am UTC](https://discuss.elastic.co/t/how-to-forward-all-logs/339653 "2023-07-31T07:20:41Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![willsy](https://avatars.discourse-cdn.com/v4/letter/w/f17d59/32.png) [@willsy](https://discuss.elastic.co/u/willsy)\
**Post date:** [July 31, 2023, 7:20am UTC](https://discuss.elastic.co/t/how-to-forward-all-logs/339653/1 "2023-07-31T07:20:41Z")

</div>

I have the following logstash configuration file that successfully sends information to a third party location.

Effectively what i am asking is, how do i constantly send ALL the data going into elastic to this third party location. Is is a data stream thing? scroll? size? and also what would be the configuration in the index and query part of this to get ALL documents to send.

```auto

input {
 elasticsearch {
 hosts => "localhost:9200"
 ssl_enabled => true
 ssl_verification_mode => none
 api_key => "XXxxXXxxXXxxXX"
index => "logs-windows.powershell-default"
 query => '{ "query": { "query_string": { "query": "*" } } }'
 size => 60
 scroll => "60m"
 docinfo => true
 docinfo_target => "[@metadata][doc]"
}
}

output {
tcp {
host => "xxx.xxx.xxx.xxx"
port => xxxxx
codec => json_lines  
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 28, 2023, 7:21am UTC](https://discuss.elastic.co/t/how-to-forward-all-logs/339653/2 "2023-08-28T07:21:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
