<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reroute data that is marked for an index? in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59086#M818</link>
    <description>&lt;P&gt;We have data from this host that is going to indexA.  I really want to be able to keep my hands off the LWF configuration so I don't have to set those up.&lt;/P&gt;</description>
    <pubDate>Thu, 30 Sep 2010 06:07:57 GMT</pubDate>
    <dc:creator>the_wolverine</dc:creator>
    <dc:date>2010-09-30T06:07:57Z</dc:date>
    <item>
      <title>Reroute data that is marked for an index?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59079#M811</link>
      <description>&lt;P&gt;I have syslog-ng data coming from LWFs that have been earmarked for indexA.  I want to intercept these events and reroute them to another index called indexB.  It doesn't seem to be working.  Am I missing something basic?&lt;/P&gt;

&lt;P&gt;The sourcetype is syslog so in props I have:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[syslog]
TRANSFORMS-route = route2indexB
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[route2indexB]
REGEX=(192.168.1.12)
DEST_KEY = _MetaData:Index
FORMAT = indexB
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I've tried multiple iterations of this configuration including using source and host in props.conf.  I can't seem to get the data to go to indexB. &lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2010 04:58:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59079#M811</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2010-09-28T04:58:12Z</dc:date>
    </item>
    <item>
      <title>Re: Reroute data that is marked for an index?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59080#M812</link>
      <description>&lt;P&gt;please provide a complete splunk diag&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2010 10:14:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59080#M812</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-09-28T10:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: Reroute data that is marked for an index?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59081#M813</link>
      <description>&lt;P&gt;You are doing IT wrong&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2010 22:40:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59081#M813</guid>
      <dc:creator>Simeon</dc:creator>
      <dc:date>2010-09-28T22:40:03Z</dc:date>
    </item>
    <item>
      <title>Re: Reroute data that is marked for an index?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59082#M814</link>
      <description>&lt;P&gt;Har Har Har, guys.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2010 23:02:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59082#M814</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2010-09-28T23:02:41Z</dc:date>
    </item>
    <item>
      <title>Re: Reroute data that is marked for an index?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59083#M815</link>
      <description>&lt;P&gt;Simeon, how am I doing IT wrong?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2010 23:19:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59083#M815</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2010-09-28T23:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: Reroute data that is marked for an index?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59084#M816</link>
      <description>&lt;P&gt;instead of doing it with props/transforms, why do you not tell the LWF to send to indexB? Rerouting with props/transforms even if possible should cause slowness in indexing...&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2010 04:50:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59084#M816</guid>
      <dc:creator>Genti</dc:creator>
      <dc:date>2010-09-29T04:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: Reroute data that is marked for an index?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59085#M817</link>
      <description>&lt;P&gt;Continuing my comment:&lt;BR /&gt;
Telling the LWF where to send the data should be cheaper (resourcewise) and quite easy.
here's an answer with a similar idea: &lt;A href="http://answers.splunk.com/questions/5134/can-i-forward-different-data-inputs-to-different-splunk-indexers-on-a-light-forwa" rel="nofollow"&gt;http://answers.splunk.com/questions/5134/can-i-forward-different-data-inputs-to-different-splunk-indexers-on-a-light-forwa&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2010 04:54:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59085#M817</guid>
      <dc:creator>Genti</dc:creator>
      <dc:date>2010-09-29T04:54:39Z</dc:date>
    </item>
    <item>
      <title>Re: Reroute data that is marked for an index?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59086#M818</link>
      <description>&lt;P&gt;We have data from this host that is going to indexA.  I really want to be able to keep my hands off the LWF configuration so I don't have to set those up.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2010 06:07:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59086#M818</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2010-09-30T06:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: Reroute data that is marked for an index?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59087#M819</link>
      <description>&lt;P&gt;Turns out the LWF was not a LWF.  It was a heavyweight forwarder &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;  &lt;/P&gt;

&lt;P&gt;Thanks to Raitz for figuring that out.  He spotted the _linebreaker in the tcpdump output which is an indication of cooked data.&lt;/P&gt;

&lt;P&gt;I had the system owner enable LWF from CLI and all is working as expected.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2010 06:09:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59087#M819</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2010-09-30T06:09:48Z</dc:date>
    </item>
    <item>
      <title>Re: Reroute data that is marked for an index?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59088#M820</link>
      <description>&lt;P&gt;Here's the tcpdump command that was run at the indexer: /usr/sbin/tcpdump -A -s 1512 host &lt;IP_ADDRESS&gt; and port 9997&lt;/IP_ADDRESS&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2010 06:13:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59088#M820</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2010-09-30T06:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: Reroute data that is marked for an index?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59089#M821</link>
      <description>&lt;P&gt;Wow. Would have been easier if you'd sent a Splunk diag.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2010 10:50:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59089#M821</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-09-30T10:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: Reroute data that is marked for an index?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59090#M822</link>
      <description>&lt;P&gt;Ghetto. If you had control over the forwarder configs, maybe you could actually be sure it was a LWF.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2010 10:51:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59090#M822</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-09-30T10:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: Reroute data that is marked for an index?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59091#M823</link>
      <description>&lt;P&gt;I'm not here to babysit forwarders &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;  Not Ghetto.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2010 22:40:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Reroute-data-that-is-marked-for-an-index/m-p/59091#M823</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2010-09-30T22:40:36Z</dc:date>
    </item>
  </channel>
</rss>

