<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forward data to two different indexers and filter a field out in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forward-data-to-two-different-indexers-and-filter-a-field-out/m-p/706088#M116789</link>
    <description>&lt;P&gt;Try to set&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;sendCookedData=false&lt;/PRE&gt;&lt;P&gt;for the second HF output in your outputs.conf and then apply your props.conf on your second HF.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Dec 2024 06:58:44 GMT</pubDate>
    <dc:creator>PaulPanther</dc:creator>
    <dc:date>2024-12-06T06:58:44Z</dc:date>
    <item>
      <title>Forward data to two different indexers and filter a field out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forward-data-to-two-different-indexers-and-filter-a-field-out/m-p/706068#M116787</link>
      <description>&lt;P&gt;I need to forward data from a heavy forwarder to two different indexer clusters. One of the clusters needs to have a field removed. If I use sedcmd in props.conf on the HF it removes it for both and putting sedcmd in props.conf on one of the indexers doesn't work (it does work if i bypass the HF).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to do this?&lt;/P&gt;&lt;P&gt;Edit: I was thinking of using an intermediate forwarder so heavy forwarder -&amp;gt; another heavy forwarder -&amp;gt; indexer cluster but the intermediate heavy forwarder props.conf does not work.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 00:29:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forward-data-to-two-different-indexers-and-filter-a-field-out/m-p/706068#M116787</guid>
      <dc:creator>klim</dc:creator>
      <dc:date>2024-12-06T00:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: Forward data to two different indexers and filter a field out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forward-data-to-two-different-indexers-and-filter-a-field-out/m-p/706088#M116789</link>
      <description>&lt;P&gt;Try to set&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;sendCookedData=false&lt;/PRE&gt;&lt;P&gt;for the second HF output in your outputs.conf and then apply your props.conf on your second HF.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 06:58:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forward-data-to-two-different-indexers-and-filter-a-field-out/m-p/706088#M116789</guid>
      <dc:creator>PaulPanther</dc:creator>
      <dc:date>2024-12-06T06:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: Forward data to two different indexers and filter a field out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forward-data-to-two-different-indexers-and-filter-a-field-out/m-p/706119#M116796</link>
      <description>&lt;P&gt;This will actually send raw data suitable to further processing by third party solution. It will not keep the metadata, it will not use s2s protocol, just send "TCP syslog" stream.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 09:19:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forward-data-to-two-different-indexers-and-filter-a-field-out/m-p/706119#M116796</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-12-06T09:19:55Z</dc:date>
    </item>
    <item>
      <title>Re: Forward data to two different indexers and filter a field out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forward-data-to-two-different-indexers-and-filter-a-field-out/m-p/706121#M116797</link>
      <description>&lt;P&gt;What is it with the latest peak of question about "sending the data into two indexer(s| clusters) while modifying one stream"? Suddenly everyone has this borderline use case?&lt;/P&gt;&lt;P&gt;Why do that in the first place? Is it really worth paying extra for double the license? What actually is your use case?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 09:24:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forward-data-to-two-different-indexers-and-filter-a-field-out/m-p/706121#M116797</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-12-06T09:24:14Z</dc:date>
    </item>
  </channel>
</rss>

