<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarding events to 2 indexer clusters but transform one copy in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Forwarding-events-to-2-indexer-clusters-but-transform-one-copy/m-p/705974#M20965</link>
    <description>Hi&lt;BR /&gt;you told here what is your solution to your issue, but what is your issue and especially why you are sending same event to two separate clusters? That means also duplicate licenses costs.&lt;BR /&gt;&lt;BR /&gt;Basically you could do this by replicating sourcetype and then removed this field from replicated sourcetype. But maybe there is better solution when we understand your real issue?&lt;BR /&gt;r.Ismo</description>
    <pubDate>Wed, 04 Dec 2024 22:46:58 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2024-12-04T22:46:58Z</dc:date>
    <item>
      <title>Forwarding events to 2 indexer clusters but transform one copy</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Forwarding-events-to-2-indexer-clusters-but-transform-one-copy/m-p/705959#M20964</link>
      <description>&lt;P&gt;I have a heavy forwarder that sends the same event to two different indexer cluster. Now this event has a new field "X" that I only want to see in one of the indexer clusters.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know in the props.conf I can configure the sourcetype to do the removal of the field but that would be on the sourcetype level. Is there any way to remove it on one copy and not the other?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alternatively I could do the props.conf change on the indexer level instead.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 21:05:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Forwarding-events-to-2-indexer-clusters-but-transform-one-copy/m-p/705959#M20964</guid>
      <dc:creator>klim</dc:creator>
      <dc:date>2024-12-04T21:05:17Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding events to 2 indexer clusters but transform one copy</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Forwarding-events-to-2-indexer-clusters-but-transform-one-copy/m-p/705974#M20965</link>
      <description>Hi&lt;BR /&gt;you told here what is your solution to your issue, but what is your issue and especially why you are sending same event to two separate clusters? That means also duplicate licenses costs.&lt;BR /&gt;&lt;BR /&gt;Basically you could do this by replicating sourcetype and then removed this field from replicated sourcetype. But maybe there is better solution when we understand your real issue?&lt;BR /&gt;r.Ismo</description>
      <pubDate>Wed, 04 Dec 2024 22:46:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Forwarding-events-to-2-indexer-clusters-but-transform-one-copy/m-p/705974#M20965</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-12-04T22:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding events to 2 indexer clusters but transform one copy</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Forwarding-events-to-2-indexer-clusters-but-transform-one-copy/m-p/706023#M20966</link>
      <description>&lt;P&gt;What business problem are you trying to solve? There has been lately an "outbreak" of ideas in line of "I want to send my events to two destinations but not as a precise copy".&lt;/P&gt;&lt;P&gt;Sending the same events to two different indexer( cluster)?s induces extra license consumption but also blocks one output when the other one is blocked so it makes your environment sensitive to any problems.&lt;/P&gt;&lt;P&gt;So back to the original question - what problem are you trying to solve?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 10:18:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Forwarding-events-to-2-indexer-clusters-but-transform-one-copy/m-p/706023#M20966</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-12-05T10:18:02Z</dc:date>
    </item>
  </channel>
</rss>

