<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Index redirection in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Index-redirection/m-p/581079#M102475</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241016"&gt;@francois&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;do you want to redirect the logs by Indexers or by Heavy Forwarders?&lt;/P&gt;&lt;P&gt;If you want to use HFs, you can find all instructions at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.4/Forwarding/Routeandfilterdatad#Replicate_a_subset_of_data_to_a_third-party_system" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.4/Forwarding/Routeandfilterdatad#Replicate_a_subset_of_data_to_a_third-party_system&lt;/A&gt;&lt;/P&gt;&lt;P&gt;in this case, put attention to the volume of syslogs: I had problems with large volume of syslogs.&lt;/P&gt;&lt;P&gt;If you want to send from Indexers, you could use the Splunk Connect for Syslogs Apps (&lt;A href="https://splunkbase.splunk.com/app/4740/#/details" target="_blank"&gt;https://splunkbase.splunk.com/app/4740/#/details&lt;/A&gt;) that can help you.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Fri, 14 Jan 2022 11:21:04 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-01-14T11:21:04Z</dc:date>
    <item>
      <title>Index redirection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-redirection/m-p/581077#M102473</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We are setting up a Splunk infrastructure where we would like to redirect event coming in particular indexes to an external SOC.&lt;/P&gt;&lt;P&gt;For example, logs from multiple firewall technologies would be put into the index "clientX_firewall" by an SC4S and this whole index would have to be forwarded to both my indexing tier and the external SOC, whatever the sourcetype / host / source.&lt;/P&gt;&lt;P&gt;Is there a way to properly redirect this whole index ? Without having to specify the source / host / sourcetype involved for each type involved ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 11:13:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-redirection/m-p/581077#M102473</guid>
      <dc:creator>francois</dc:creator>
      <dc:date>2022-01-14T11:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: Index redirection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-redirection/m-p/581078#M102474</link>
      <description>&lt;P&gt;I think you need to do a syslogrouting on hf and send everything to indexer and that external location from there with outputs.conf having config for both&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 11:17:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-redirection/m-p/581078#M102474</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2022-01-14T11:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: Index redirection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-redirection/m-p/581079#M102475</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241016"&gt;@francois&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;do you want to redirect the logs by Indexers or by Heavy Forwarders?&lt;/P&gt;&lt;P&gt;If you want to use HFs, you can find all instructions at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.4/Forwarding/Routeandfilterdatad#Replicate_a_subset_of_data_to_a_third-party_system" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.4/Forwarding/Routeandfilterdatad#Replicate_a_subset_of_data_to_a_third-party_system&lt;/A&gt;&lt;/P&gt;&lt;P&gt;in this case, put attention to the volume of syslogs: I had problems with large volume of syslogs.&lt;/P&gt;&lt;P&gt;If you want to send from Indexers, you could use the Splunk Connect for Syslogs Apps (&lt;A href="https://splunkbase.splunk.com/app/4740/#/details" target="_blank"&gt;https://splunkbase.splunk.com/app/4740/#/details&lt;/A&gt;) that can help you.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 11:21:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-redirection/m-p/581079#M102475</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-01-14T11:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: Index redirection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-redirection/m-p/581083#M102476</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Thank you for your response,&lt;/P&gt;&lt;P&gt;Once the event has been processed by the SC4S (Splunk-connect-for-syslog), it is sent as HTTP so I don't think I'll have a problem with volume. From the documentation, a single SC4S instance with proper hardware requirements can handle up to 6TB/day.&lt;/P&gt;&lt;P&gt;The events will be replicated on my heavy forwarder, I did try the method described on&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.4/Forwarding/Routeandfilterdatad#Replicate_a_subset_of_data_to_a_third-party_system" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.4/Forwarding/Routeandfilterdatad#Replicate_a_subset_of_data_to_a_third-party_system&lt;/A&gt;&amp;nbsp;but using this method, I'd have to create an entry in my props.conf for each source / host /sourcetype. This would mean a lot of repetitive / unnecessary work to maintain.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It would be much simpler to be able to replicate an entire index to a third party system.&lt;/P&gt;&lt;P&gt;Do you know if it is possible ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&amp;nbsp;&lt;/P&gt;&lt;P&gt;François.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 12:40:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-redirection/m-p/581083#M102476</guid>
      <dc:creator>francois</dc:creator>
      <dc:date>2022-01-14T12:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: Index redirection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-redirection/m-p/581086#M102477</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241016"&gt;@francois&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;my hint is to use the Syslog Connect App, but you need a search as input for it, this means that you have to&amp;nbsp; use it on Indexers or configure your Heavy Forwarder as a Search Head or to duplicate data to forward on the HF.&lt;/P&gt;&lt;P&gt;For these reasons I hint to use it on Indexers or on Search Heads.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 13:09:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-redirection/m-p/581086#M102477</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-01-14T13:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: Index redirection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-redirection/m-p/581094#M102478</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry I don't understand your answer. Syslog-connect ( &lt;A href="https://splunkbase.splunk.com/app/4740/#/details" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/4740/#/details&lt;/A&gt; ) is, per my understanding, not an app but an appliance (containerized syslog-ng with pre-defined filters) that allows for syslog traffic to be properly categorized into sourcetype, host, index, etc. and then sent to an HEC.&lt;/P&gt;&lt;P&gt;Therefore :&lt;/P&gt;&lt;P&gt;1. How can I install this on a search head / Indexer ?&lt;/P&gt;&lt;P&gt;2. How can I pass seaches as inputs ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 13:45:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-redirection/m-p/581094#M102478</guid>
      <dc:creator>francois</dc:creator>
      <dc:date>2022-01-14T13:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: Index redirection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-redirection/m-p/581099#M102479</link>
      <description>&lt;P&gt;What I would check (but I'm not sure if it will work that's why I say I'd check it first) is matching to some wildcard in props.conf to apply a transform and then in that transform matching to a particular index metadata field.&lt;/P&gt;&lt;P&gt;But as I said - haven't tried it, that's just a quick idea from the top of my head.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 13:58:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-redirection/m-p/581099#M102479</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-01-14T13:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: Index redirection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-redirection/m-p/581100#M102480</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241016"&gt;@francois&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Splunk is a software solution hardware indipendent.&lt;/P&gt;&lt;P&gt;The Syslog Connect for Splunk is an App to install on a Full Splunk instance (all except Universal Forwarders).&lt;/P&gt;&lt;P&gt;You can install it on an Indexer or a Search Head because you have to execute a search and the results are the input for the App for sending to a third party system.&lt;/P&gt;&lt;P&gt;You can also install it on an Heavy Forwarder, but HFs usually don't access data so you have to configure it as a Search Head or locally index a copy of the data to send to third party, but this solution is expensive because you duplicate the license consuption.&lt;/P&gt;&lt;P&gt;This app is usually used for syslog ingesting but it also offers features for syslog sending to third party.&lt;/P&gt;&lt;P&gt;I used it in a project to send a part of logs to an external SIEM.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 13:58:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-redirection/m-p/581100#M102480</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-01-14T13:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: Index redirection</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-redirection/m-p/581449#M102510</link>
      <description>&lt;P&gt;Thanks for your help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We ended up using the stanza "default" in the props.conf and sending it to various transforms.conf group so that it can match multiple regex.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 12:30:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-redirection/m-p/581449#M102510</guid>
      <dc:creator>francois</dc:creator>
      <dc:date>2022-01-18T12:30:18Z</dc:date>
    </item>
  </channel>
</rss>

