<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Configure indexer cluster to send one index to splunk(standalone, not  in architecture) in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Configure-indexer-cluster-to-send-one-index-to-splunk-standalone/m-p/554390#M6018</link>
    <description>&lt;P&gt;Hi, i have a problem with sending one index from indexer cluster to another standalone Splunk instance. I have&amp;nbsp; a 4 indexers, replication factor = 3 . How should I configure my cluster to send only 1 index? I tried to install UF on indexer and monitor the index directory. The event was in wrong format. Also tried to configure forwarding all events in indexer to standalone splunk, and then filter to receive only one index. But nothing came of it.&amp;nbsp;&lt;/P&gt;&lt;LI-SPOILER&gt;&amp;nbsp;&lt;/LI-SPOILER&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Jun 2021 04:59:15 GMT</pubDate>
    <dc:creator>Dias</dc:creator>
    <dc:date>2021-06-04T04:59:15Z</dc:date>
    <item>
      <title>Configure indexer cluster to send one index to splunk(standalone, not  in architecture)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Configure-indexer-cluster-to-send-one-index-to-splunk-standalone/m-p/554390#M6018</link>
      <description>&lt;P&gt;Hi, i have a problem with sending one index from indexer cluster to another standalone Splunk instance. I have&amp;nbsp; a 4 indexers, replication factor = 3 . How should I configure my cluster to send only 1 index? I tried to install UF on indexer and monitor the index directory. The event was in wrong format. Also tried to configure forwarding all events in indexer to standalone splunk, and then filter to receive only one index. But nothing came of it.&amp;nbsp;&lt;/P&gt;&lt;LI-SPOILER&gt;&amp;nbsp;&lt;/LI-SPOILER&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 04:59:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Configure-indexer-cluster-to-send-one-index-to-splunk-standalone/m-p/554390#M6018</guid>
      <dc:creator>Dias</dc:creator>
      <dc:date>2021-06-04T04:59:15Z</dc:date>
    </item>
    <item>
      <title>Re: Configure indexer cluster to send one index to splunk(standalone, not  in architecture)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Configure-indexer-cluster-to-send-one-index-to-splunk-standalone/m-p/558791#M6349</link>
      <description>&lt;P&gt;We decided to make a standalone instance to be searchhead. And then make a user, with access to only one index&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 04:47:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Configure-indexer-cluster-to-send-one-index-to-splunk-standalone/m-p/558791#M6349</guid>
      <dc:creator>Dias</dc:creator>
      <dc:date>2021-07-09T04:47:32Z</dc:date>
    </item>
  </channel>
</rss>

