<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows Event Log Configurations for Dual Forwarding in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Log-Configurations-for-Dual-Forwarding/m-p/691633#M115022</link>
    <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;&lt;P&gt;We have requirement to monitor wineventlogswith sourcename MSSQL and will be sent to different sets of IDX.&lt;/P&gt;&lt;P&gt;For global IDX,&amp;nbsp; the wineventlogs inputs will be sourcename MSSQL only&lt;BR /&gt;For abc-region, the&amp;nbsp;wineventlogs inputs will be sourcename MSSQL and&amp;nbsp;ComputerName with ending in "abc.com" domain (e.g. XXXXX.abc.com, YYYY.abc.com).&lt;/P&gt;&lt;P&gt;With this, is the configurations below correct? Looking forward to your insights.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;##########################################&lt;BR /&gt;inputs.conf&lt;BR /&gt;#####################################&lt;BR /&gt;[WinEventLog://Application]&lt;BR /&gt;index=mssql_idx&lt;BR /&gt;whitelist= SourceName=%MSSQL%&lt;BR /&gt;sourcetype=mssql:app&lt;BR /&gt;disabled=false&lt;BR /&gt;_TCP_ROUTING=idx-all-global&lt;BR /&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[WinEventLog://Application]&lt;BR /&gt;index=mssql_idx&lt;BR /&gt;whitelist= SourceName=%MSSQL% ComputerName=%abc.com%&lt;BR /&gt;sourcetype=mssql:app&lt;BR /&gt;disabled=false&lt;BR /&gt;_TCP_ROUTING=idx-abc-region&lt;BR /&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/P&gt;&lt;P&gt;##########################################&lt;BR /&gt;outputs.conf&lt;BR /&gt;##########################################&lt;/P&gt;&lt;P&gt;[indexAndForward]&lt;BR /&gt;index=false&lt;/P&gt;&lt;P&gt;[tcpout]&lt;BR /&gt;defaultGroup= idx-all-global, idx-abc-region&lt;/P&gt;&lt;P&gt;[tcpout:idx-all-global]&lt;BR /&gt;server=global-idx1:9997, global-idx2:9997&lt;/P&gt;&lt;P&gt;[tcpout:idx-abc-region]&lt;BR /&gt;server= abc-region-idx1:9997, abc-region-idx2:9997&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 26 Jun 2024 07:47:02 GMT</pubDate>
    <dc:creator>jaracan</dc:creator>
    <dc:date>2024-06-26T07:47:02Z</dc:date>
    <item>
      <title>Windows Event Log Configurations for Dual Forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Log-Configurations-for-Dual-Forwarding/m-p/691633#M115022</link>
      <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;&lt;P&gt;We have requirement to monitor wineventlogswith sourcename MSSQL and will be sent to different sets of IDX.&lt;/P&gt;&lt;P&gt;For global IDX,&amp;nbsp; the wineventlogs inputs will be sourcename MSSQL only&lt;BR /&gt;For abc-region, the&amp;nbsp;wineventlogs inputs will be sourcename MSSQL and&amp;nbsp;ComputerName with ending in "abc.com" domain (e.g. XXXXX.abc.com, YYYY.abc.com).&lt;/P&gt;&lt;P&gt;With this, is the configurations below correct? Looking forward to your insights.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;##########################################&lt;BR /&gt;inputs.conf&lt;BR /&gt;#####################################&lt;BR /&gt;[WinEventLog://Application]&lt;BR /&gt;index=mssql_idx&lt;BR /&gt;whitelist= SourceName=%MSSQL%&lt;BR /&gt;sourcetype=mssql:app&lt;BR /&gt;disabled=false&lt;BR /&gt;_TCP_ROUTING=idx-all-global&lt;BR /&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[WinEventLog://Application]&lt;BR /&gt;index=mssql_idx&lt;BR /&gt;whitelist= SourceName=%MSSQL% ComputerName=%abc.com%&lt;BR /&gt;sourcetype=mssql:app&lt;BR /&gt;disabled=false&lt;BR /&gt;_TCP_ROUTING=idx-abc-region&lt;BR /&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/P&gt;&lt;P&gt;##########################################&lt;BR /&gt;outputs.conf&lt;BR /&gt;##########################################&lt;/P&gt;&lt;P&gt;[indexAndForward]&lt;BR /&gt;index=false&lt;/P&gt;&lt;P&gt;[tcpout]&lt;BR /&gt;defaultGroup= idx-all-global, idx-abc-region&lt;/P&gt;&lt;P&gt;[tcpout:idx-all-global]&lt;BR /&gt;server=global-idx1:9997, global-idx2:9997&lt;/P&gt;&lt;P&gt;[tcpout:idx-abc-region]&lt;BR /&gt;server= abc-region-idx1:9997, abc-region-idx2:9997&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 07:47:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Log-Configurations-for-Dual-Forwarding/m-p/691633#M115022</guid>
      <dc:creator>jaracan</dc:creator>
      <dc:date>2024-06-26T07:47:02Z</dc:date>
    </item>
  </channel>
</rss>

