<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to forward events coming from HTTP event collector to multiple indexers? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-coming-from-HTTP-event-collector-to/m-p/215205#M42376</link>
    <description>&lt;P&gt;I'm looking to setup a VIP for this, but when using port 8089 as the VIP Health Check it keeps showing as down. Has anyone configured a VIP for the HEC?&lt;/P&gt;</description>
    <pubDate>Thu, 13 Jul 2017 13:26:08 GMT</pubDate>
    <dc:creator>cxj</dc:creator>
    <dc:date>2017-07-13T13:26:08Z</dc:date>
    <item>
      <title>How to forward events coming from HTTP event collector to multiple indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-coming-from-HTTP-event-collector-to/m-p/215202#M42373</link>
      <description>&lt;P&gt;The HTTP event collector is working fine. I need to forward the http events to multiple Splunk indexers. &lt;/P&gt;

&lt;P&gt;How should the configs be set up?&lt;BR /&gt;
Could you provide an example?  &lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Lp&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2016 15:46:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-coming-from-HTTP-event-collector-to/m-p/215202#M42373</guid>
      <dc:creator>lpolo</dc:creator>
      <dc:date>2016-08-08T15:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward events coming from HTTP event collector to multiple indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-coming-from-HTTP-event-collector-to/m-p/215203#M42374</link>
      <description>&lt;P&gt;You could be more explicit in describing what you are trying to do.&lt;/P&gt;

&lt;P&gt;You could create a DNS alias for all your indexers and forward to the DNS name.&lt;/P&gt;

&lt;P&gt;You could also create a VIP using a load-balancer and forward to the VIP.&lt;/P&gt;

&lt;P&gt;Finally if you just want the http events balanced among your indexers, you could set up a heavy forwarder, send all the events to it and then have it load balance it's ouput (via outputs.conf) to all indexers.&lt;/P&gt;

&lt;P&gt;Pick one.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2016 15:54:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-coming-from-HTTP-event-collector-to/m-p/215203#M42374</guid>
      <dc:creator>sjohnson_splunk</dc:creator>
      <dc:date>2016-08-08T15:54:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward events coming from HTTP event collector to multiple indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-coming-from-HTTP-event-collector-to/m-p/215204#M42375</link>
      <description>&lt;P&gt;My money will be one last option (using HF and Splunk's LB to send data to multiple indexers)&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2016 16:11:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-coming-from-HTTP-event-collector-to/m-p/215204#M42375</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-08-08T16:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward events coming from HTTP event collector to multiple indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-coming-from-HTTP-event-collector-to/m-p/215205#M42376</link>
      <description>&lt;P&gt;I'm looking to setup a VIP for this, but when using port 8089 as the VIP Health Check it keeps showing as down. Has anyone configured a VIP for the HEC?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 13:26:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-coming-from-HTTP-event-collector-to/m-p/215205#M42376</guid>
      <dc:creator>cxj</dc:creator>
      <dc:date>2017-07-13T13:26:08Z</dc:date>
    </item>
  </channel>
</rss>

