<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic route attribute in inputs.conf in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/route-attribute-in-inputs-conf/m-p/213125#M41868</link>
    <description>&lt;P&gt;Can someone could explain the route attribute in inputs.conf&lt;/P&gt;

&lt;P&gt;[splunktcp]&lt;BR /&gt;
route = haskey..&lt;/P&gt;

&lt;P&gt;What is matching rule here mentioned&lt;/P&gt;</description>
    <pubDate>Fri, 05 Aug 2016 13:56:08 GMT</pubDate>
    <dc:creator>splunkn</dc:creator>
    <dc:date>2016-08-05T13:56:08Z</dc:date>
    <item>
      <title>route attribute in inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/route-attribute-in-inputs-conf/m-p/213125#M41868</link>
      <description>&lt;P&gt;Can someone could explain the route attribute in inputs.conf&lt;/P&gt;

&lt;P&gt;[splunktcp]&lt;BR /&gt;
route = haskey..&lt;/P&gt;

&lt;P&gt;What is matching rule here mentioned&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2016 13:56:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/route-attribute-in-inputs-conf/m-p/213125#M41868</guid>
      <dc:creator>splunkn</dc:creator>
      <dc:date>2016-08-05T13:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: route attribute in inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/route-attribute-in-inputs-conf/m-p/213126#M41869</link>
      <description>&lt;P&gt;The only time I've seen that setting used is when you want to re-parse cooked data.  If you have data from a heavy forwarder going to an indexer, normally none of the indexer's index time props and transforms apply.  This is because the data has already been 'cooked' (processed) by the heavy forwarder.  You can change the route to force data to pass through parsing queues it would normally skip.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/97918/reparsing-cooked-data-coming-from-a-heavy-forwarder-possible.html"&gt;https://answers.splunk.com/answers/97918/reparsing-cooked-data-coming-from-a-heavy-forwarder-possible.html&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/305740/why-is-data-received-from-a-remote-splunk-instance.html"&gt;https://answers.splunk.com/answers/305740/why-is-data-received-from-a-remote-splunk-instance.html&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/5528/forwarding-select-data-in-my-environment.html"&gt;https://answers.splunk.com/answers/5528/forwarding-select-data-in-my-environment.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Don't confuse this setting with more commonly used data routing settings, where you might want to forward some data to a 3rd party, to a different set of indexers, or drop a subset of events:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.2/Forwarding/Routeandfilterdatad"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.2/Forwarding/Routeandfilterdatad&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2016 14:24:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/route-attribute-in-inputs-conf/m-p/213126#M41869</guid>
      <dc:creator>Jeremiah</dc:creator>
      <dc:date>2016-08-05T14:24:43Z</dc:date>
    </item>
  </channel>
</rss>

