<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to forward data to a remote app from a Splunk instance that is currently both a search head and indexer? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-to-a-remote-app-from-a-Splunk-instance-that/m-p/231475#M45083</link>
    <description>&lt;P&gt;We have a well established Splunk app on an instance which is serving as a Search Head and an Indexer. However, there are some data there which needs to be forwarded to some other site, which hosts a different application. Some of the data comes from a modular input (receiving some TCP traffic), but there are others, like *hix TA, which we would also like to forward to that other app at a different site.&lt;/P&gt;

&lt;P&gt;Is there any trick to do that? Any special settings I need to have in &lt;CODE&gt;inputs.conf&lt;/CODE&gt; and &lt;CODE&gt;outputs.conf&lt;/CODE&gt; to work properly and not disturb the main operation, which has quite a few indexes and wants its data locally?&lt;/P&gt;</description>
    <pubDate>Wed, 17 Aug 2016 17:26:48 GMT</pubDate>
    <dc:creator>arkadyz1</dc:creator>
    <dc:date>2016-08-17T17:26:48Z</dc:date>
    <item>
      <title>How to forward data to a remote app from a Splunk instance that is currently both a search head and indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-to-a-remote-app-from-a-Splunk-instance-that/m-p/231475#M45083</link>
      <description>&lt;P&gt;We have a well established Splunk app on an instance which is serving as a Search Head and an Indexer. However, there are some data there which needs to be forwarded to some other site, which hosts a different application. Some of the data comes from a modular input (receiving some TCP traffic), but there are others, like *hix TA, which we would also like to forward to that other app at a different site.&lt;/P&gt;

&lt;P&gt;Is there any trick to do that? Any special settings I need to have in &lt;CODE&gt;inputs.conf&lt;/CODE&gt; and &lt;CODE&gt;outputs.conf&lt;/CODE&gt; to work properly and not disturb the main operation, which has quite a few indexes and wants its data locally?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2016 17:26:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-to-a-remote-app-from-a-Splunk-instance-that/m-p/231475#M45083</guid>
      <dc:creator>arkadyz1</dc:creator>
      <dc:date>2016-08-17T17:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward data to a remote app from a Splunk instance that is currently both a search head and indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-to-a-remote-app-from-a-Splunk-instance-that/m-p/231476#M45084</link>
      <description>&lt;P&gt;Hi arkadyz1, You'll want to reference the documentation here : &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.2/Forwarding/Routeandfilterdatad"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.2/Forwarding/Routeandfilterdatad&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Please let me know if this helps!&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2016 17:56:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-to-a-remote-app-from-a-Splunk-instance-that/m-p/231476#M45084</guid>
      <dc:creator>muebel</dc:creator>
      <dc:date>2016-08-17T17:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward data to a remote app from a Splunk instance that is currently both a search head and indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-to-a-remote-app-from-a-Splunk-instance-that/m-p/231477#M45085</link>
      <description>&lt;P&gt;Can you review the documentation &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.2/Forwarding/Forwarddatatothird-partysystemsd"&gt;here&lt;/A&gt; and let us know if this doesn't give you the information you are looking for?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2016 17:57:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-to-a-remote-app-from-a-Splunk-instance-that/m-p/231477#M45085</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2016-08-17T17:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward data to a remote app from a Splunk instance that is currently both a search head and indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-to-a-remote-app-from-a-Splunk-instance-that/m-p/231478#M45086</link>
      <description>&lt;P&gt;Sorry I can't accept both answers - the links provided gave me all the info I needed. It's a non-trivial switch from universal forwarder's _TCP_ROUTING (in inputs.conf) to the heavy forwarder, with the info spread between four (!) files - &lt;CODE&gt;inputs.conf&lt;/CODE&gt;, &lt;CODE&gt;outputs.conf&lt;/CODE&gt;, &lt;CODE&gt;props.conf&lt;/CODE&gt; and &lt;CODE&gt;transforms.conf&lt;/CODE&gt;).&lt;/P&gt;

&lt;P&gt;In addition, we need to rename the sourcetypes from Splunk_TA_nix - being an OEM, we are allowed only the sourcetypes from a predefined list. Is it best done on the receiving system?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:46:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-to-a-remote-app-from-a-Splunk-instance-that/m-p/231478#M45086</guid>
      <dc:creator>arkadyz1</dc:creator>
      <dc:date>2020-09-29T10:46:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward data to a remote app from a Splunk instance that is currently both a search head and indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-to-a-remote-app-from-a-Splunk-instance-that/m-p/231479#M45087</link>
      <description>&lt;P&gt;Just to recap my experience, and as a word of caution to others who might read this question:&lt;/P&gt;

&lt;P&gt;As soon as you define a forwarding server, the whole Splunk instance turns into a Heavy Forwarder, and everything, including the stuff normally going into _internal, gets forwarded (extremely counterintuitive to me). This is actually documented, but you might easily skip over that part if you search the docs for the specific instructions without reading the whole chapter.&lt;/P&gt;

&lt;P&gt;So, what one needs in the case like mine:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Enable &lt;STRONG&gt;selective forwarding&lt;/STRONG&gt;. For that you need to add the following stanza somewhere among your outputs.conf files:&lt;/P&gt;

&lt;P&gt;[indexAndForward]&lt;BR /&gt;
index=true&lt;BR /&gt;
selectiveIndexing=true&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Mark each and every input you want to be kept locally (and yes, this includes the files listed in etc/system/default/inputs.conf) as such. Use &lt;CODE&gt;_INDEX_AND_FORWARD_ROUTING&lt;/CODE&gt; property in the corresponding input stanza for that.&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;A simple but an error-prone procedure - it's easy to forget about an input you want to index locally.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2016 14:46:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-to-a-remote-app-from-a-Splunk-instance-that/m-p/231479#M45087</guid>
      <dc:creator>arkadyz1</dc:creator>
      <dc:date>2016-09-29T14:46:45Z</dc:date>
    </item>
  </channel>
</rss>

