<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: forwarding logs through props.conf in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/forwarding-logs-through-props-conf/m-p/541857#M5083</link>
    <description>&lt;P&gt;probably the indexAndFoward setting&lt;/P&gt;&lt;P&gt;It would be greatly helpful if you include your props and transforms.&amp;nbsp; Also please review the splunk docs for routing and filtering data.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.2/Forwarding/Routeandfilterdatad" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.2/Forwarding/Routeandfilterdatad&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 01 Mar 2021 20:32:30 GMT</pubDate>
    <dc:creator>jodonald</dc:creator>
    <dc:date>2021-03-01T20:32:30Z</dc:date>
    <item>
      <title>forwarding logs through props.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/forwarding-logs-through-props-conf/m-p/541333#M5045</link>
      <description>&lt;P&gt;Hi guys. i´m trying to forward some events to another indexer usin my configuration files props.conf, transforms.conf and outputs.conf but the problem is that when I do it I forward all my data and not onlt the index and sourcetype that I want to forward even though I´m sure of applying those filters correctly on my props.conf&amp;nbsp;&lt;/P&gt;&lt;P&gt;What could be happening?&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 12:46:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/forwarding-logs-through-props-conf/m-p/541333#M5045</guid>
      <dc:creator>franciscof</dc:creator>
      <dc:date>2021-02-25T12:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: forwarding logs through props.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/forwarding-logs-through-props-conf/m-p/541857#M5083</link>
      <description>&lt;P&gt;probably the indexAndFoward setting&lt;/P&gt;&lt;P&gt;It would be greatly helpful if you include your props and transforms.&amp;nbsp; Also please review the splunk docs for routing and filtering data.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.2/Forwarding/Routeandfilterdatad" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.2/Forwarding/Routeandfilterdatad&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 20:32:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/forwarding-logs-through-props-conf/m-p/541857#M5083</guid>
      <dc:creator>jodonald</dc:creator>
      <dc:date>2021-03-01T20:32:30Z</dc:date>
    </item>
    <item>
      <title>Re: forwarding logs through props.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/forwarding-logs-through-props-conf/m-p/542165#M5114</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is my props.conf located on /opt/splunk/etc/apps/search/local&lt;/P&gt;&lt;P&gt;[f5:bigip:syslog]&lt;BR /&gt;TRANSFORMS-routing = routeLT&lt;BR /&gt;index = test_f5&lt;BR /&gt;source = tcp:9515&lt;/P&gt;&lt;P&gt;Here is my transforms.conf located on /opt/splunk/etc/apps/search/local&lt;/P&gt;&lt;P&gt;[routeLT]&lt;BR /&gt;REGEX=(\w+?\-?\w+\-\w+(?:\-\w+)?\:\:\w+\-?\d?\.\"\S+\"\s+\=\s+\".*\"|\d+\/\d+\/\d+\s+[\d\:]+\s+\-\S+\s+.action\=ping\s+\S+\n\S+.+\n.+ms)&lt;BR /&gt;DEST_KEY=_TCP_ROUTING&lt;BR /&gt;FORMAT=LightTech, default-autolb-group&lt;/P&gt;&lt;P&gt;Here is my inputs.conf located on /opt/splunk/etc/apps/search/local&lt;/P&gt;&lt;P&gt;[tcp://9515]&lt;BR /&gt;connection_host = ip&lt;BR /&gt;index = test_f5&lt;BR /&gt;sourcetype = f5:bigip:syslog&lt;BR /&gt;_TCP_ROUTING = LighTech&lt;/P&gt;&lt;P&gt;And here is my outputs.conf located on /opt/splunk/etc/system/local&lt;/P&gt;&lt;P&gt;[tcpout]&lt;BR /&gt;forwardedindex.filter.disable = true&lt;BR /&gt;indexAndForward = true&lt;/P&gt;&lt;P&gt;[tcpout:LighTech]&lt;BR /&gt;server = 190.210.177.194:9997&lt;/P&gt;&lt;P&gt;[indexAndForward]&lt;BR /&gt;index = true&lt;/P&gt;&lt;P&gt;What could be wrong?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 13:37:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/forwarding-logs-through-props-conf/m-p/542165#M5114</guid>
      <dc:creator>franciscof</dc:creator>
      <dc:date>2021-03-03T13:37:23Z</dc:date>
    </item>
  </channel>
</rss>

