Hi,
Is there a way to nest the Output statement so that I can first output using the CEF codec and then Output to a Kafka topic. The requirement is that I have to covert the data to CEF and then send to a Kafka topic. I feel like I can just use the server and port of the Kafka server but I am not sure how to send it to a specific topic on that server. Will just adding "topic_id" work? or does it have to be nested differently?
output {
tcp {
port => "KAFKA SERVER PORT"
host => "192,168.1.1,192.168.1.2"
**topic_id => "mytopic"**
codec => cef {
delimiter => "\r\n"
fields => [ "cs1", "cs2", "cs3"]
version => "1"
severity => "7"
}
}
}