<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: _TCP_ROUTING for Heavy Forwarder in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-ROUTING-for-Heavy-Forwarder/m-p/430839#M52851</link>
    <description>&lt;P&gt;Yes it does. I have 2 stanzas one for FirewallEvents and one for FirewallAudit.  I added _TCP_ROUTING under both the stanzas in inputs.conf but did not specify that in the question. &lt;/P&gt;

&lt;P&gt;Another interesting thing: We are using Splunk_TA_box on HF and these events are also not routed to fw_cluster even after explicitly defining _TCP_ROUTING under stanza. &lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 21:39:47 GMT</pubDate>
    <dc:creator>sudosplunk</dc:creator>
    <dc:date>2020-09-29T21:39:47Z</dc:date>
    <item>
      <title>_TCP_ROUTING for Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-ROUTING-for-Heavy-Forwarder/m-p/430837#M52849</link>
      <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;

&lt;P&gt;I've a situation where _TCP_ROUTING setting in inputs.conf is not being honored by splunk. Here is my architecture and related config files.&lt;/P&gt;

&lt;P&gt;HF --&amp;gt; Indexer cluster&lt;/P&gt;

&lt;P&gt;On HF, $SPLUNK_HOME/etc/apps/Splunk_TA_checkpoint/local/opseclea_inputs.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[FirewallEvents]
_TCP_ROUTING = fw_cluster
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;On HF, $SPLUNK_HOME/etc/apps/route_outputs/local/outpus.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
indexAndForward = false
defaultGroup = main_cluster
autoLBFrequency = 15

[tcpout:main_cluster]
server = mainIDX1:9997,mainIDX2:9997,mainIDX3:9997,mainIDX4:9997
useACK = true
maxQueueSize = 7MB

[tcpout:fw_cluster]
server = fwIDX1:9997,fwIDX2:9997,fwIDX3:9997,fwIDX4:9997
useACK = true
maxQueueSize = 7MB
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Events are still being routed to &lt;CODE&gt;main_cluster&lt;/CODE&gt; instead of &lt;CODE&gt;fw_cluster&lt;/CODE&gt;. This kind of routing is working for other data sources coming through UFs. &lt;/P&gt;

&lt;P&gt;I've already reviewed metrics.log and splunkd.log and validated HF is making TCPInput connections to indexers (fw_cluster).&lt;/P&gt;

&lt;P&gt;Any advise on troubleshooting is appreciated. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:39:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-ROUTING-for-Heavy-Forwarder/m-p/430837#M52849</guid>
      <dc:creator>sudosplunk</dc:creator>
      <dc:date>2020-09-29T21:39:44Z</dc:date>
    </item>
    <item>
      <title>Re: _TCP_ROUTING for Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-ROUTING-for-Heavy-Forwarder/m-p/430838#M52850</link>
      <description>&lt;P&gt;It's been a while since I've worked with the opsec lea addon, but doesn't that generate multiple input stanzas, one for each log collection you define in the opsec add-on GUI? So shouldn't you be adding that _TCP_routing setting in each of those generated input.conf sections?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:43:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-ROUTING-for-Heavy-Forwarder/m-p/430838#M52850</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2020-09-29T21:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: _TCP_ROUTING for Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-ROUTING-for-Heavy-Forwarder/m-p/430839#M52851</link>
      <description>&lt;P&gt;Yes it does. I have 2 stanzas one for FirewallEvents and one for FirewallAudit.  I added _TCP_ROUTING under both the stanzas in inputs.conf but did not specify that in the question. &lt;/P&gt;

&lt;P&gt;Another interesting thing: We are using Splunk_TA_box on HF and these events are also not routed to fw_cluster even after explicitly defining _TCP_ROUTING under stanza. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:39:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-ROUTING-for-Heavy-Forwarder/m-p/430839#M52851</guid>
      <dc:creator>sudosplunk</dc:creator>
      <dc:date>2020-09-29T21:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: _TCP_ROUTING for Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-ROUTING-for-Heavy-Forwarder/m-p/430840#M52852</link>
      <description>&lt;P&gt;What is &lt;CODE&gt;_TCP_ROUTING&lt;/CODE&gt; for this specific input when running &lt;CODE&gt;./splunk cmd btool inputs list --debug&lt;/CODE&gt;?&lt;/P&gt;</description>
      <pubDate>Sun, 21 Oct 2018 21:25:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-ROUTING-for-Heavy-Forwarder/m-p/430840#M52852</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-10-21T21:25:57Z</dc:date>
    </item>
    <item>
      <title>Re: _TCP_ROUTING for Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-ROUTING-for-Heavy-Forwarder/m-p/430841#M52853</link>
      <description>&lt;P&gt;Hi @ddrillic, splunk is able to recognize the setting from input.conf of only &lt;CODE&gt;Splunk_TA_box&lt;/CODE&gt; but not &lt;CODE&gt;Splunk_TA_checkpoint&lt;/CODE&gt;.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[splunk@HF ~]$ /splunk/bin/splunk btool inputs list --debug | grep '_TCP_ROUTING'
/splunk/etc/apps/Splunk_TA_box/local/inputs.conf                   _TCP_ROUTING = fw_cluster
/splunk/etc/system/default/inputs.conf                             _TCP_ROUTING = *
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sun, 21 Oct 2018 21:32:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-ROUTING-for-Heavy-Forwarder/m-p/430841#M52853</guid>
      <dc:creator>sudosplunk</dc:creator>
      <dc:date>2018-10-21T21:32:18Z</dc:date>
    </item>
    <item>
      <title>Re: _TCP_ROUTING for Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-ROUTING-for-Heavy-Forwarder/m-p/430842#M52854</link>
      <description>&lt;P&gt;Anything that &lt;CODE&gt;./splunk cmd btool check&lt;/CODE&gt; reports? maybe a syntax error...&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 00:55:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-ROUTING-for-Heavy-Forwarder/m-p/430842#M52854</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-10-22T00:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: _TCP_ROUTING for Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-ROUTING-for-Heavy-Forwarder/m-p/430844#M52856</link>
      <description>&lt;P&gt;Hi @ddrillic ,&lt;/P&gt;

&lt;P&gt;Below is the output. Based on this output and @coccyx answer, I believe that &lt;CODE&gt;_TCP_ROUTING&lt;/CODE&gt; setting doesn't work for modular inputs.  &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[splunk@HF local]$ /splunk/bin/splunk cmd btool check
                Invalid key in stanza [FirewallEvents] in /splunk/etc/apps/Splunk_TA_checkpoint-opseclea/local/opseclea_inputs.conf, line 2: _TCP_ROUTING  (value:  fw_cluster).
                Invalid key in stanza [FirewallAudit] in /splunk/etc/apps/Splunk_TA_checkpoint-opseclea/local/opseclea_inputs.conf, line 12: _TCP_ROUTING  (value:  fw_cluster).
[splunk@pespl027 local]$
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 25 Oct 2018 13:13:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-ROUTING-for-Heavy-Forwarder/m-p/430844#M52856</guid>
      <dc:creator>sudosplunk</dc:creator>
      <dc:date>2018-10-25T13:13:19Z</dc:date>
    </item>
    <item>
      <title>Re: _TCP_ROUTING for Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-ROUTING-for-Heavy-Forwarder/m-p/430846#M52858</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Routing with pros.conf and transforms.conf instead of inputs.conf should do the job:&lt;/P&gt;

&lt;P&gt;props:&lt;/P&gt;

&lt;P&gt;[opsec]&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;TRANSFORMS-route=routefw_cluster
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[routefw_cluster]

REGEX=.+
DEST_KEY=_TCP_ROUTING
FORMAT=fw_cluster
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Best regards,&lt;/P&gt;

&lt;P&gt;Andreas&lt;/P&gt;</description>
      <pubDate>Thu, 22 Nov 2018 15:08:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-ROUTING-for-Heavy-Forwarder/m-p/430846#M52858</guid>
      <dc:creator>schose</dc:creator>
      <dc:date>2018-11-22T15:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: _TCP_ROUTING for Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-ROUTING-for-Heavy-Forwarder/m-p/686040#M80559</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/143135"&gt;@sudosplunk&lt;/a&gt;&amp;nbsp;the setting is expected to be in inputs.conf ( not in custom inputs.conf).&lt;BR /&gt;All modinputs honor meta setting starting 6.4&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/UF-Route-inputs-to-specific-indexers-based-on-the-data-s-input/m-p/147597" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/UF-Route-inputs-to-specific-indexers-based-on-the-data-s-input/m-p/147597&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2024 10:20:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-ROUTING-for-Heavy-Forwarder/m-p/686040#M80559</guid>
      <dc:creator>hrawat</dc:creator>
      <dc:date>2024-05-01T10:20:06Z</dc:date>
    </item>
  </channel>
</rss>

