<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarde data based on sourcetype between 2 indexers or between indexer and search head in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Forwarde-data-based-on-sourcetype-between-2-indexers-or-between/m-p/510737#M2781</link>
    <description>&lt;P&gt;Please say more about that. Why the SH and not the indexer where the data resides? What third-party software)?&lt;BR /&gt;I think your &lt;FONT face="courier new,courier"&gt;defaultGroup&lt;/FONT&gt; attribute needs a value that is not "my_search_head_group".&lt;BR /&gt;Have you read &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/Forwarding/Forwarddatatothird-partysystemsd" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.5/Forwarding/Forwarddatatothird-partysystemsd&lt;/A&gt;?&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jul 2020 20:38:57 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-07-23T20:38:57Z</dc:date>
    <item>
      <title>Forwarde data based on sourcetype between 2 indexers or between indexer and search head</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Forwarde-data-based-on-sourcetype-between-2-indexers-or-between/m-p/510486#M2746</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Il would like to know if i could forward data based on sourcetype between 2 indexers or between indexer and search head.&lt;/P&gt;&lt;P&gt;Il would like to forward only data of a certain sourcetype.&lt;/P&gt;&lt;P&gt;Thank you for your help&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 15:55:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Forwarde-data-based-on-sourcetype-between-2-indexers-or-between/m-p/510486#M2746</guid>
      <dc:creator>myitlab1000</dc:creator>
      <dc:date>2020-07-22T15:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarde data based on sourcetype between 2 indexers or between indexer and search head</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Forwarde-data-based-on-sourcetype-between-2-indexers-or-between/m-p/510498#M2749</link>
      <description>Forwarding between indexers is possible. Forwarding from indexer to search head does not make sense since search heads do not store data.&lt;BR /&gt;What problem are you trying to solve?</description>
      <pubDate>Wed, 22 Jul 2020 17:25:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Forwarde-data-based-on-sourcetype-between-2-indexers-or-between/m-p/510498#M2749</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-22T17:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarde data based on sourcetype between 2 indexers or between indexer and search head</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Forwarde-data-based-on-sourcetype-between-2-indexers-or-between/m-p/510506#M2750</link>
      <description>&lt;P&gt;I have multiple indexers and one search head.&lt;/P&gt;&lt;P&gt;forwarders =&amp;gt; Indexer 1, Indexer 2, Indexer N =&amp;gt; search head =&amp;gt; forwarding to third party&lt;/P&gt;&lt;P&gt;I can forward data but the problem is that is forwarding all the data.&lt;/P&gt;&lt;P&gt;Il would like to index all data locally to indexer and forward only data based on certain sourcetype by the search head to avoid open additional port between indexers and the third party software.&lt;/P&gt;&lt;P&gt;I have tested by configuring props.conf, transforms.conf and outputs.conf, but still forwarding all data, all sourcetype.&lt;/P&gt;&lt;P&gt;reference docs : &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/Forwarding/Routeandfilterdatad" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.5/Forwarding/Routeandfilterdatad&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for your help&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 18:01:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Forwarde-data-based-on-sourcetype-between-2-indexers-or-between/m-p/510506#M2750</guid>
      <dc:creator>myitlab1000</dc:creator>
      <dc:date>2020-07-22T18:01:57Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarde data based on sourcetype between 2 indexers or between indexer and search head</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Forwarde-data-based-on-sourcetype-between-2-indexers-or-between/m-p/510519#M2752</link>
      <description>How are you specifying the sourcetype to forward?</description>
      <pubDate>Wed, 22 Jul 2020 19:15:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Forwarde-data-based-on-sourcetype-between-2-indexers-or-between/m-p/510519#M2752</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-22T19:15:13Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarde data based on sourcetype between 2 indexers or between indexer and search head</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Forwarde-data-based-on-sourcetype-between-2-indexers-or-between/m-p/510593#M2762</link>
      <description>&lt;P&gt;Here is my conf of an indexer to forward to search head and from search i would like to forward to third party.&lt;/P&gt;&lt;P&gt;The problem is not only data of soucetype "&lt;STRONG&gt;mysourcetype&lt;/STRONG&gt;" is forwarded but all data.&lt;/P&gt;&lt;P&gt;in props.conf:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[mysourcetype]&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TRANSFORMS-routing = forward_to_my_search_head_from_indexer&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in transforms.conf:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[forward_to_my_search_head_from_indexer]&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;REGEX = .&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;DEST_KEY = _TCP_ROUTING&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;FORMAT = my_search_head_group&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in outpus.conf:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[tcpout]&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;defaultGroup = nothing&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;indexAndForward = true&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[tcpout:my_search_head_group]&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;disable = false&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;server = my_search_head_ip:9997&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;sendCookedData = false&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for yo&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 07:26:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Forwarde-data-based-on-sourcetype-between-2-indexers-or-between/m-p/510593#M2762</guid>
      <dc:creator>myitlab1000</dc:creator>
      <dc:date>2020-07-23T07:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarde data based on sourcetype between 2 indexers or between indexer and search head</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Forwarde-data-based-on-sourcetype-between-2-indexers-or-between/m-p/510683#M2770</link>
      <description>Your configuration appears to make sense according to the documentation, however, I still cannot wrap my head around why you are forwarding data from an indexer to a search head. That is not a normal practice. Can you describe your Splunk architecture? What problem are you trying to solve by forwarding data from indexer to SH?</description>
      <pubDate>Thu, 23 Jul 2020 15:00:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Forwarde-data-based-on-sourcetype-between-2-indexers-or-between/m-p/510683#M2770</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-23T15:00:10Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarde data based on sourcetype between 2 indexers or between indexer and search head</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Forwarde-data-based-on-sourcetype-between-2-indexers-or-between/m-p/510715#M2774</link>
      <description>&lt;P&gt;I would like to expose one port from SH to external (third party software).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 18:27:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Forwarde-data-based-on-sourcetype-between-2-indexers-or-between/m-p/510715#M2774</guid>
      <dc:creator>myitlab1000</dc:creator>
      <dc:date>2020-07-23T18:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarde data based on sourcetype between 2 indexers or between indexer and search head</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Forwarde-data-based-on-sourcetype-between-2-indexers-or-between/m-p/510737#M2781</link>
      <description>&lt;P&gt;Please say more about that. Why the SH and not the indexer where the data resides? What third-party software)?&lt;BR /&gt;I think your &lt;FONT face="courier new,courier"&gt;defaultGroup&lt;/FONT&gt; attribute needs a value that is not "my_search_head_group".&lt;BR /&gt;Have you read &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/Forwarding/Forwarddatatothird-partysystemsd" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.5/Forwarding/Forwarddatatothird-partysystemsd&lt;/A&gt;?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 20:38:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Forwarde-data-based-on-sourcetype-between-2-indexers-or-between/m-p/510737#M2781</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-23T20:38:57Z</dc:date>
    </item>
  </channel>
</rss>

