Hi Mark,
I think the easiest setup for your requirements would be to forward the
messages processed by the locked down Graylog2 server to the user-facing
Graylog2 server via the GELF output. This way you could filter messages or
run extractors in exactly one place and just forward the final
Is the GELF data stream encrypted? Probably 95% of the reason we even use
fluentd/elastic/graylog is to meet the requirement to encrypt the data over
the wire. I pretty much do all the filtering and extraction in fluentd on
the secure_senders. I think pretty much any government or corporate