<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarding and cloning specific index's to a third party splunk indexer in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Forwarding-and-cloning-specific-index-s-to-a-third-party-splunk/m-p/517632#M3221</link>
    <description>&lt;P&gt;props.conf:&lt;/P&gt;&lt;P&gt;[thesourcetype]&lt;BR /&gt;TRANSFORMS-route = route_to_third_party&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;transforms.conf:&lt;/P&gt;&lt;P&gt;[route_to_third_party]&lt;BR /&gt;SOURCE_KEY = _MetaData:Index&lt;BR /&gt;REGEX = ^(winevent)$&lt;BR /&gt;DEST_KEY=_TCP_ROUTING&lt;BR /&gt;FORMAT = mysplunkinstance, thirdpartyinoutputsconf&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Perhaps?&lt;/P&gt;</description>
    <pubDate>Thu, 03 Sep 2020 04:17:04 GMT</pubDate>
    <dc:creator>gjanders</dc:creator>
    <dc:date>2020-09-03T04:17:04Z</dc:date>
    <item>
      <title>Forwarding and cloning specific index's to a third party splunk indexer</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Forwarding-and-cloning-specific-index-s-to-a-third-party-splunk/m-p/517573#M3216</link>
      <description>If a party decided to split all events into their own index's (IE. winevent_security to "security", winevernt_application to "application" etc), but then they had a third party security group that needed specific index's (in this case just the security index). How would one set it up to where that index still goes to the main splunk for the company but ONLY that log goes to the third party splunk as well. The idea is to use a heavy forwarder, but I am not sure how to specify the index. Right now I have all index's going to both but that is not a solution that everyone is comfortable with. Any help would be amazing.</description>
      <pubDate>Wed, 02 Sep 2020 19:48:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Forwarding-and-cloning-specific-index-s-to-a-third-party-splunk/m-p/517573#M3216</guid>
      <dc:creator>troyfredmsit</dc:creator>
      <dc:date>2020-09-02T19:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding and cloning specific index's to a third party splunk indexer</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Forwarding-and-cloning-specific-index-s-to-a-third-party-splunk/m-p/517632#M3221</link>
      <description>&lt;P&gt;props.conf:&lt;/P&gt;&lt;P&gt;[thesourcetype]&lt;BR /&gt;TRANSFORMS-route = route_to_third_party&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;transforms.conf:&lt;/P&gt;&lt;P&gt;[route_to_third_party]&lt;BR /&gt;SOURCE_KEY = _MetaData:Index&lt;BR /&gt;REGEX = ^(winevent)$&lt;BR /&gt;DEST_KEY=_TCP_ROUTING&lt;BR /&gt;FORMAT = mysplunkinstance, thirdpartyinoutputsconf&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Perhaps?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 04:17:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Forwarding-and-cloning-specific-index-s-to-a-third-party-splunk/m-p/517632#M3221</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2020-09-03T04:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding and cloning specific index's to a third party splunk indexer</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Forwarding-and-cloning-specific-index-s-to-a-third-party-splunk/m-p/517740#M3237</link>
      <description>&lt;P&gt;it can be done, see &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/Forwarding/Routeandfilterdatad" target="_self"&gt;Forwarding/Route and filter data&lt;/A&gt;&amp;nbsp; and CLONE_SOURCETYPE in &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/Admin/Transformsconf" target="_self"&gt;Transforms.conf&lt;/A&gt; . But be warned, it becomes complicated and cumbersome if your rule set is large. You may look into &lt;A href="https://www.splunk.com/en_us/software/stream-processing.html" target="_self"&gt;Splunk Data Stream Processor, DSP&lt;/A&gt; or also a certain third party product, for a solution which scales.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 14:22:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Forwarding-and-cloning-specific-index-s-to-a-third-party-splunk/m-p/517740#M3237</guid>
      <dc:creator>FritzWittwer</dc:creator>
      <dc:date>2020-09-03T14:22:04Z</dc:date>
    </item>
  </channel>
</rss>

