<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: multiple indexes in distrubuted splunk environment in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/multiple-indexes-in-distrubuted-splunk-environment/m-p/61122#M12137</link>
    <description>&lt;P&gt;Please see &lt;A href="http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings%3F" rel="nofollow"&gt;http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings%3F&lt;/A&gt; for a general explanation.&lt;/P&gt;</description>
    <pubDate>Thu, 30 Sep 2010 10:41:11 GMT</pubDate>
    <dc:creator>gkanapathy</dc:creator>
    <dc:date>2010-09-30T10:41:11Z</dc:date>
    <item>
      <title>multiple indexes in distrubuted splunk environment</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/multiple-indexes-in-distrubuted-splunk-environment/m-p/61120#M12135</link>
      <description>&lt;P&gt;Before I ask my question, this is my environment.&lt;/P&gt;

&lt;P&gt;1 forwarder&lt;/P&gt;

&lt;P&gt;4 indexers&lt;/P&gt;

&lt;P&gt;1 search head&lt;/P&gt;

&lt;P&gt;I am trying to setup several indexes (based on source types).&lt;/P&gt;

&lt;P&gt;I have created indexes on each of the indexers (ct_usertransaction), and setup rules according to the documentation. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;props.conf (on forwarder)
[ct-UserTransaction]
TRANSFORMS-index = ct-UserTransaction


[ct-UserTransaction]
DEST_KEY = MetaData:Index
REGEX = (ct-UserTransaction:)
FORMAT = ct_usertransaction
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But I don't see anything in ct_usertransaction index.&lt;/P&gt;

&lt;P&gt;Where do I need to configure the rules, on a forwarder or indexers?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2010 09:11:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/multiple-indexes-in-distrubuted-splunk-environment/m-p/61120#M12135</guid>
      <dc:creator>ultra</dc:creator>
      <dc:date>2010-09-30T09:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: multiple indexes in distrubuted splunk environment</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/multiple-indexes-in-distrubuted-splunk-environment/m-p/61121#M12136</link>
      <description>&lt;P&gt;You need to set this configuration on the indexer for lightweight forwarders and on the forwarder for heavyweight forwarders.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2010 09:39:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/multiple-indexes-in-distrubuted-splunk-environment/m-p/61121#M12136</guid>
      <dc:creator>Stephen_Sorkin</dc:creator>
      <dc:date>2010-09-30T09:39:01Z</dc:date>
    </item>
    <item>
      <title>Re: multiple indexes in distrubuted splunk environment</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/multiple-indexes-in-distrubuted-splunk-environment/m-p/61122#M12137</link>
      <description>&lt;P&gt;Please see &lt;A href="http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings%3F" rel="nofollow"&gt;http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings%3F&lt;/A&gt; for a general explanation.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2010 10:41:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/multiple-indexes-in-distrubuted-splunk-environment/m-p/61122#M12137</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-09-30T10:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: multiple indexes in distrubuted splunk environment</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/multiple-indexes-in-distrubuted-splunk-environment/m-p/61123#M12138</link>
      <description>&lt;P&gt;Thank you very much for this. It is a helpful link.&lt;/P&gt;

&lt;P&gt;But it raises another question. &lt;BR /&gt;
How do I route specific events from a heavy weight forwarder to a specific index on a remote indexer?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Oct 2010 01:33:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/multiple-indexes-in-distrubuted-splunk-environment/m-p/61123#M12138</guid>
      <dc:creator>ultra</dc:creator>
      <dc:date>2010-10-01T01:33:56Z</dc:date>
    </item>
  </channel>
</rss>

