<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk heavy forwarding, how to index logs on receiving end in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-heavy-forwarding-how-to-index-logs-on-receiving-end/m-p/572415#M101306</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240139"&gt;@balajivs&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;let me understand:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;you have two machines, both configured as Heavy Forwarders (HF1 and HF2),&lt;/LI&gt;&lt;LI&gt;HF1 has to send logs to HF2, is it correct?&lt;/LI&gt;&lt;LI&gt;I can suppose that you have also at least another machine configured as Indexer that will finally receive logs, is it correct?&lt;/LI&gt;&lt;LI&gt;Does HF2 locally stores a copy of data or does it forwards all the data to the Indexer?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Anyway, if HF1 locally inputs logs, you can configure the index in the inputs.conf file.&lt;/P&gt;&lt;P&gt;If instead HF1 receive and forwards logs, you have to configure selective indexing and forwarding in HF1 as described at&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.2/Forwarding/Routeandfilterdatad#Perform_selective_indexing_and_forwarding" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.2/Forwarding/Routeandfilterdatad#Perform_selective_indexing_and_forwarding&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Tue, 26 Oct 2021 10:15:28 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2021-10-26T10:15:28Z</dc:date>
    <item>
      <title>Splunk heavy forwarding, how to index logs on receiving end</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-heavy-forwarding-how-to-index-logs-on-receiving-end/m-p/572408#M101304</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;I have configured Splunk heavy forwarder in 2 machines. I want to send logs from one machine to another and expect the receiver to store all the received logs in an index called "&lt;STRONG&gt;receivedlogs&lt;/STRONG&gt;".&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;This is the video I followed to configure Splunk:&amp;nbsp;&lt;A href="https://www.youtube.com/watch?v=S4ekkH5mv3E&amp;amp;t=454s&amp;amp;ab_channel=Splunk%26MachineLearning" target="_blank"&gt;https://www.youtube.com/watch?v=S4ekkH5mv3E&amp;amp;t=454s&amp;amp;ab_channel=Splunk%26MachineLearning&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2021 09:53:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-heavy-forwarding-how-to-index-logs-on-receiving-end/m-p/572408#M101304</guid>
      <dc:creator>balajivs</dc:creator>
      <dc:date>2021-10-26T09:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk heavy forwarding, how to index logs on receiving end</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-heavy-forwarding-how-to-index-logs-on-receiving-end/m-p/572415#M101306</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240139"&gt;@balajivs&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;let me understand:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;you have two machines, both configured as Heavy Forwarders (HF1 and HF2),&lt;/LI&gt;&lt;LI&gt;HF1 has to send logs to HF2, is it correct?&lt;/LI&gt;&lt;LI&gt;I can suppose that you have also at least another machine configured as Indexer that will finally receive logs, is it correct?&lt;/LI&gt;&lt;LI&gt;Does HF2 locally stores a copy of data or does it forwards all the data to the Indexer?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Anyway, if HF1 locally inputs logs, you can configure the index in the inputs.conf file.&lt;/P&gt;&lt;P&gt;If instead HF1 receive and forwards logs, you have to configure selective indexing and forwarding in HF1 as described at&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.2/Forwarding/Routeandfilterdatad#Perform_selective_indexing_and_forwarding" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.2/Forwarding/Routeandfilterdatad#Perform_selective_indexing_and_forwarding&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2021 10:15:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-heavy-forwarding-how-to-index-logs-on-receiving-end/m-p/572415#M101306</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-10-26T10:15:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk heavy forwarding, how to index logs on receiving end</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-heavy-forwarding-how-to-index-logs-on-receiving-end/m-p/572432#M101307</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;On machine 1 have configured inputs.conf such a way that it will monitor locally stored logs. The output.conf is configured to send those locally stored logs to machine 2's port 9997. Machine 2 is listening to port 9997 and it by default stores the logs received on index "main".&lt;BR /&gt;I want to store logs received from 9997 port to a specific index called "&lt;STRONG&gt;receivedlogs".&amp;nbsp;&lt;/STRONG&gt;I tried going through the documentation you mentioned but I was unable to find a proper solution.&lt;BR /&gt;&lt;BR /&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2021 11:25:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-heavy-forwarding-how-to-index-logs-on-receiving-end/m-p/572432#M101307</guid>
      <dc:creator>balajivs</dc:creator>
      <dc:date>2021-10-26T11:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk heavy forwarding, how to index logs on receiving end</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-heavy-forwarding-how-to-index-logs-on-receiving-end/m-p/572433#M101308</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240139"&gt;@balajivs&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I try to translate:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;HF1 is the log source,&lt;/LI&gt;&lt;LI&gt;if you have only to take logs, you don't need an Heavy Forwarder (that as it's named it's an heavy monitoring systema), probably you could use an Universal Forwarder that's lighter;&lt;/LI&gt;&lt;LI&gt;HF2, isn't an Heavy Forwarder but an Indexer.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Now, you have two choices to define the index:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;on the first machine, you could insert the index definition in the inputs;&lt;/LI&gt;&lt;LI&gt;on the second machine, you could use the selective indexing I described in my previous answer.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I hint to define index in the first machine, you can do this in many ways:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;editing inputs.conf on the first machine and adding "index =&amp;nbsp;receivedlogs" in the stanza related to the log input;&lt;/LI&gt;&lt;LI&gt;otherwise, you can open the web gui at the page you used to configure input and in the middle of the window there's a field "index" where you can define the index to store logs, if you don't see the index listed in the dropdown, you have to use the other solution or create a local empty index with the same name.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2021 11:37:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-heavy-forwarding-how-to-index-logs-on-receiving-end/m-p/572433#M101308</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-10-26T11:37:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk heavy forwarding, how to index logs on receiving end</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-heavy-forwarding-how-to-index-logs-on-receiving-end/m-p/572435#M101309</link>
      <description>&lt;P&gt;Also, correct me if I'm wrong, if OP choses to write the messages localy to an index on the indexer and also forward the to another splunk instance where they will get separately indexed, the indexed events will consume the license twice - once on the intermediate indexer, once on the destination indexer.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2021 11:48:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-heavy-forwarding-how-to-index-logs-on-receiving-end/m-p/572435#M101309</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-26T11:48:47Z</dc:date>
    </item>
  </channel>
</rss>

