<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Group data forwarded by a list of hosts into different buckets in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Group-data-forwarded-by-a-list-of-hosts-into-different-buckets/m-p/19189#M2688</link>
    <description>&lt;P&gt;Great!  You can do it on the server too, I will add that example.&lt;/P&gt;</description>
    <pubDate>Fri, 31 Dec 2010 05:28:32 GMT</pubDate>
    <dc:creator>araitz</dc:creator>
    <dc:date>2010-12-31T05:28:32Z</dc:date>
    <item>
      <title>Group data forwarded by a list of hosts into different buckets</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Group-data-forwarded-by-a-list-of-hosts-into-different-buckets/m-p/19183#M2682</link>
      <description>&lt;P&gt;I've got 4 splunk instances running,  with 3 light forwarders sending application logs to my main 'server' instance (i've configured this via forwarding in the management console of my server instance)&lt;/P&gt;

&lt;P&gt;It's working great, but I need some way to group or separate the incoming data into different buckets of logs.&lt;/P&gt;

&lt;P&gt;For example, I'd like to have the logs from my collection of development environments going into a development index, that only the development user is allow to see and search.&lt;/P&gt;

&lt;P&gt;I want to do the same thing for a collection of other environments and users.&lt;/P&gt;

&lt;P&gt;What's the easiest approach to this?  The buckets are qualified by the hostnames the logs are coming from.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2010 07:46:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Group-data-forwarded-by-a-list-of-hosts-into-different-buckets/m-p/19183#M2682</guid>
      <dc:creator>mhessick</dc:creator>
      <dc:date>2010-12-30T07:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: Group data forwarded by a list of hosts into different buckets</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Group-data-forwarded-by-a-list-of-hosts-into-different-buckets/m-p/19184#M2683</link>
      <description>&lt;P&gt;Can you describe you use case a bit more? What do you mean by buckets? Do you need different indexes for this data? Or do you just need to have separation of data at search time?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2010 07:53:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Group-data-forwarded-by-a-list-of-hosts-into-different-buckets/m-p/19184#M2683</guid>
      <dc:creator>Simon_Shelston</dc:creator>
      <dc:date>2010-12-30T07:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: Group data forwarded by a list of hosts into different buckets</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Group-data-forwarded-by-a-list-of-hosts-into-different-buckets/m-p/19185#M2684</link>
      <description>&lt;P&gt;A bucket is just a generic term some place that's separate from other places.  I suppose either a separation at search time or a different index would both work. &lt;/P&gt;

&lt;P&gt;As long as users could be restricted from viewing an index or logs  . . . by their role.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2010 08:04:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Group-data-forwarded-by-a-list-of-hosts-into-different-buckets/m-p/19185#M2684</guid>
      <dc:creator>mhessick</dc:creator>
      <dc:date>2010-12-30T08:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: Group data forwarded by a list of hosts into different buckets</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Group-data-forwarded-by-a-list-of-hosts-into-different-buckets/m-p/19186#M2685</link>
      <description>&lt;P&gt;As long as the aggregation of the incoming logs doesn't go into 1 big searchable index  . . .that's kind of what i'm looking for.  I want to assign a role to be able to view only a specific index and direct incoming logs from a set of hostnames to a specified index.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2010 08:12:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Group-data-forwarded-by-a-list-of-hosts-into-different-buckets/m-p/19186#M2685</guid>
      <dc:creator>mhessick</dc:creator>
      <dc:date>2010-12-30T08:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: Group data forwarded by a list of hosts into different buckets</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Group-data-forwarded-by-a-list-of-hosts-into-different-buckets/m-p/19187#M2686</link>
      <description>&lt;P&gt;Set up different indexes (for example 'dev'):&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.splunk.com/base/Documentation/4.1.6/Admin/Setupmultipleindexes" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.1.6/Admin/Setupmultipleindexes&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Specify what index data should go to what index via inputs.conf on the forwarder:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.splunk.com/base/Documentation/4.1.6/Admin/Inputsconf" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.1.6/Admin/Inputsconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///path/to/devfiles/]
sourcetype=foo
index=dev
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;EM&gt;Alternately&lt;/EM&gt;, you can control the destination index on the indexer if the data is coming from a lightweight forwarder.  You can do this OR you can set the index on the forwarder - you do not need to do both.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.splunk.com/base/Documentation/4.1.6/Admin/Propsconf" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.1.6/Admin/Propsconf&lt;/A&gt;:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[host::some_dev_host]
TRANSFORMS-foo=route_to_dev_index
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;A href="http://www.splunk.com/base/Documentation/4.1.6/Admin/Transformsconf" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.1.6/Admin/Transformsconf&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[route_to_dev_index]
REGEX=.
DEST_KEY=_MetaData:Index
FORMAT=dev
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Create roles and constrain the roles to the proper indexes:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.splunk.com/base/Documentation/4.1.6/Admin/Addusersandassignroles#Add_and_edit_roles_using_Splunk_Web" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.1.6/Admin/Addusersandassignroles#Add_and_edit_roles_using_Splunk_Web&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Add users to those roles, and you are done.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2010 08:31:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Group-data-forwarded-by-a-list-of-hosts-into-different-buckets/m-p/19187#M2686</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2010-12-30T08:31:54Z</dc:date>
    </item>
    <item>
      <title>Re: Group data forwarded by a list of hosts into different buckets</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Group-data-forwarded-by-a-list-of-hosts-into-different-buckets/m-p/19188#M2687</link>
      <description>&lt;P&gt;This works great.  I had previously specified the indexes on the server (because the indexes only existed there)  &lt;/P&gt;

&lt;P&gt;When I changed that and specified the indexes on the forwarders, everything worked.&lt;/P&gt;

&lt;P&gt;Thanks a ton.&lt;/P&gt;

&lt;P&gt;-Mike&lt;/P&gt;</description>
      <pubDate>Fri, 31 Dec 2010 04:11:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Group-data-forwarded-by-a-list-of-hosts-into-different-buckets/m-p/19188#M2687</guid>
      <dc:creator>mhessick</dc:creator>
      <dc:date>2010-12-31T04:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: Group data forwarded by a list of hosts into different buckets</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Group-data-forwarded-by-a-list-of-hosts-into-different-buckets/m-p/19189#M2688</link>
      <description>&lt;P&gt;Great!  You can do it on the server too, I will add that example.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Dec 2010 05:28:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Group-data-forwarded-by-a-list-of-hosts-into-different-buckets/m-p/19189#M2688</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2010-12-31T05:28:32Z</dc:date>
    </item>
  </channel>
</rss>

