<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Redirection to multiple indexes and Null queue not working in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Redirection-to-multiple-indexes-and-Null-queue-not-working/m-p/574805#M101587</link>
    <description>&lt;P&gt;What results do you get?&lt;/P&gt;&lt;P&gt;If there are no other configuration items pertaining to your sources (have you tried btool props list?) I'd say that you redirect all matching sources (do you match properly? Are you sure you shouldn't use "..." instead of "*"?) to nullqueue so the index rewriting is a bit pointless since all events should get discarded in the end.&lt;/P&gt;</description>
    <pubDate>Sat, 13 Nov 2021 10:49:47 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2021-11-13T10:49:47Z</dc:date>
    <item>
      <title>Redirection to multiple indexes and Null queue not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Redirection-to-multiple-indexes-and-Null-queue-not-working/m-p/574803#M101586</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are integrating the json logs via HEC into Splunk Heavy Forwarder.&lt;BR /&gt;I have tried the below configurations.I am applying the props for the source. In transforms, there are different regexes and I would want to route it to different indexes based on log files and route all the other files not required to a null queue. I would not be able to use FORMAT=indexqueue in transforms.conf as I cannot mention multiple indexes in inputs.conf .This is not working and I am not getting results as expected. Kindly help.&lt;/P&gt;&lt;P&gt;The configs are like below:&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;PROPS.CONF --&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;[source::*model-app*]&lt;BR /&gt;TRANSFORMS-segment=setnull,security_logs,application_logs,provisioning_logs&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;TRANSFORMS.CONF --&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[setnull]&lt;BR /&gt;REGEX=class\"\:\"(.*?)\"&lt;BR /&gt;DEST_KEY = queue&lt;BR /&gt;FORMAT = nullQueue&lt;/P&gt;&lt;P&gt;[security_logs]&lt;BR /&gt;REGEX=(class\"\:\"(/var/log/cron|/var/log/audit/audit.log|/var/log/messages|/var/log/secure)\")&lt;BR /&gt;DEST_KEY=_MetaData:Index&lt;BR /&gt;FORMAT=model_sec&lt;BR /&gt;WRITE_META=true&lt;BR /&gt;LOOKAHEAD=40000&lt;/P&gt;&lt;P&gt;[application_logs]&lt;BR /&gt;REGEX=(class\"\:\"(/var/log/application.log|/var/log/local*?.log)\")&lt;BR /&gt;DEST_KEY=_MetaData:Index&lt;BR /&gt;FORMAT=model_app&lt;BR /&gt;WRITE_META=true&lt;BR /&gt;LOOKAHEAD=40000&lt;/P&gt;&lt;P&gt;[provisioning_logs]&lt;BR /&gt;REGEX=class\"\:\"(/opt/provgw-error_msg.log|/opt/provgw-bulkrequest.log|/opt/provgw/provgw-spml_command.log.*?)\"&lt;BR /&gt;DEST_KEY=_MetaData:Index&lt;BR /&gt;FORMAT=model_prov&lt;BR /&gt;WRITE_META=true&lt;/P&gt;</description>
      <pubDate>Sat, 13 Nov 2021 09:29:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Redirection-to-multiple-indexes-and-Null-queue-not-working/m-p/574803#M101586</guid>
      <dc:creator>bhargavi</dc:creator>
      <dc:date>2021-11-13T09:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: Redirection to multiple indexes and Null queue not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Redirection-to-multiple-indexes-and-Null-queue-not-working/m-p/574805#M101587</link>
      <description>&lt;P&gt;What results do you get?&lt;/P&gt;&lt;P&gt;If there are no other configuration items pertaining to your sources (have you tried btool props list?) I'd say that you redirect all matching sources (do you match properly? Are you sure you shouldn't use "..." instead of "*"?) to nullqueue so the index rewriting is a bit pointless since all events should get discarded in the end.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Nov 2021 10:49:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Redirection-to-multiple-indexes-and-Null-queue-not-working/m-p/574805#M101587</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-13T10:49:47Z</dc:date>
    </item>
  </channel>
</rss>

