<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder sending two sets of Windows Security Logs to two different indexer in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-sending-two-sets-of-Windows-Security-Logs-to/m-p/573252#M101407</link>
    <description>&lt;P&gt;Can you configure indexer2?&lt;BR /&gt;If possible, you set nullqueue on indexer2. If not possible, I think you need to deploy HF between UF and indexers.&lt;BR /&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;The following posts may be helpful.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Filtering-events-using-NullQueue/m-p/66392" target="_self"&gt;https://community.splunk.com/t5/Getting-Data-In/Filtering-events-using-NullQueue/m-p/66392&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Unfortunately, &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Bandwidth control is not possible for each indexer...&lt;BR /&gt;UF have thruput in limits.conf, but&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; this parameter should be global.&lt;/P&gt;</description>
    <pubDate>Tue, 02 Nov 2021 01:17:33 GMT</pubDate>
    <dc:creator>sushi</dc:creator>
    <dc:date>2021-11-02T01:17:33Z</dc:date>
    <item>
      <title>Universal Forwarder sending two sets of Windows Security Logs to two different indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-sending-two-sets-of-Windows-Security-Logs-to/m-p/573248#M101406</link>
      <description>&lt;P&gt;I need the Universal Forwarders to send Windows Security Logs to two different indexers but the data I want to send has different criteria.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to send all win security events without a whitelist to Indexer1 and I need to send win security events with a whitelist to indexer2.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Indexer2 is in another country which will provide 24/7 SOC support and there's a bandwidth limitation.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this possible?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 23:03:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-sending-two-sets-of-Windows-Security-Logs-to/m-p/573248#M101406</guid>
      <dc:creator>minliang</dc:creator>
      <dc:date>2021-11-01T23:03:14Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder sending two sets of Windows Security Logs to two different indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-sending-two-sets-of-Windows-Security-Logs-to/m-p/573252#M101407</link>
      <description>&lt;P&gt;Can you configure indexer2?&lt;BR /&gt;If possible, you set nullqueue on indexer2. If not possible, I think you need to deploy HF between UF and indexers.&lt;BR /&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;The following posts may be helpful.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Filtering-events-using-NullQueue/m-p/66392" target="_self"&gt;https://community.splunk.com/t5/Getting-Data-In/Filtering-events-using-NullQueue/m-p/66392&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Unfortunately, &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Bandwidth control is not possible for each indexer...&lt;BR /&gt;UF have thruput in limits.conf, but&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; this parameter should be global.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 01:17:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-sending-two-sets-of-Windows-Security-Logs-to/m-p/573252#M101407</guid>
      <dc:creator>sushi</dc:creator>
      <dc:date>2021-11-02T01:17:33Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder sending two sets of Windows Security Logs to two different indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-sending-two-sets-of-Windows-Security-Logs-to/m-p/573335#M101420</link>
      <description>&lt;P&gt;Okay, I took the suggestion and basically setup index and forwarding.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have this in my transforms.prof in indexer1 to forward logs to my second index using TCP_ROUTING.&lt;/P&gt;&lt;P&gt;My new question is that how can I specify the index name to send the data to in Indexer2.&amp;nbsp;&lt;/P&gt;&lt;P&gt;[DataToForward]&lt;/P&gt;&lt;P&gt;REGEX= XYZ&lt;/P&gt;&lt;P&gt;DEST_KEY = _TCP_ROUTING&lt;/P&gt;&lt;P&gt;FORMAT = INDEXER2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 15:44:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-sending-two-sets-of-Windows-Security-Logs-to/m-p/573335#M101420</guid>
      <dc:creator>minliang</dc:creator>
      <dc:date>2021-11-02T15:44:43Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder sending two sets of Windows Security Logs to two different indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-sending-two-sets-of-Windows-Security-Logs-to/m-p/573759#M101478</link>
      <description>&lt;P&gt;Umm...I think it is not possible if 2 indexers have different index name...&lt;BR /&gt;You can only index on one indexer.&lt;/P&gt;&lt;P&gt;I tried to set following conf.&lt;BR /&gt;In default, testsourcetype is indexed to indexname1 on INDEXER1.&lt;BR /&gt;INDEXER1 don't have indexname2.&lt;BR /&gt;So, INDEXER1 cannot index events which forwarded to indexname2 on INDEXER2.&lt;/P&gt;&lt;P&gt;If you have same indexname on INDEXER1 and INDEXER2, you can index on both indexers.&lt;/P&gt;&lt;P&gt;# inputs.conf&lt;BR /&gt;[monitor://testfile]&lt;BR /&gt;sourcetype = testsourcetype&lt;BR /&gt;index = indexname1&lt;BR /&gt;&lt;BR /&gt;# props.conf&lt;BR /&gt;[testsourcetype]&lt;BR /&gt;TRANSFORMS-hogehoge = DataToForward,changeIndex&lt;BR /&gt;&lt;BR /&gt;# transforms.conf&lt;BR /&gt;[DataToForward]&lt;BR /&gt;REGEX= XYZ&lt;BR /&gt;DEST_KEY = _TCP_ROUTING&lt;BR /&gt;FORMAT = INDEXER2&lt;BR /&gt;&lt;BR /&gt;[changeIndex]&lt;BR /&gt;SOURCE_KEY = _TCP_ROUTING&lt;BR /&gt;REGEX = INDEXER2&lt;BR /&gt;DEST_KEY = _MetaData:Index&lt;BR /&gt;FORMAT = indexname2&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 08:11:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-sending-two-sets-of-Windows-Security-Logs-to/m-p/573759#M101478</guid>
      <dc:creator>sushi</dc:creator>
      <dc:date>2021-11-05T08:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder sending two sets of Windows Security Logs to two different indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-sending-two-sets-of-Windows-Security-Logs-to/m-p/573766#M101481</link>
      <description>&lt;P&gt;Please try to route the data first based upon your tcpoutputproc, for example:&lt;/P&gt;&lt;P&gt;[WinEventLog://System]&lt;/P&gt;&lt;P&gt;_TCP_ROUTING = splunkidxA,splunkidxB&lt;/P&gt;&lt;P&gt;indexer = A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As the data is received in both the indexer, try to drop unecessary event from the indexer using props and transforms. Hope this helps.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 09:21:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-sending-two-sets-of-Windows-Security-Logs-to/m-p/573766#M101481</guid>
      <dc:creator>sombhtr239</dc:creator>
      <dc:date>2021-11-05T09:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder sending two sets of Windows Security Logs to two different indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-sending-two-sets-of-Windows-Security-Logs-to/m-p/573814#M101487</link>
      <description>&lt;P&gt;Unfortunately, the "filtering" is applied to a particular input (there is no filtering capability as such on Universal Forwarder - the black/whitelisting is a functionality of this particular input). So you can't get two different data streams from a single input.&lt;/P&gt;&lt;P&gt;And most of the metadata is specified also at the input level (no advanced manipulation on UF, so no props/transforms) so the most you can do - as others already pointed out is to route the events to two destinations. It's the destination HF/indexer that you can try to manipulate the metadata on further (i.e. rewrite the index, source, sourcetype and so on).&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 12:36:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-sending-two-sets-of-Windows-Security-Logs-to/m-p/573814#M101487</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-05T12:36:17Z</dc:date>
    </item>
  </channel>
</rss>

