<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How can I forward only _internal index data from indexer to the new indexer? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-only-internal-index-data-from-indexer-to-the/m-p/291912#M55639</link>
    <description>&lt;P&gt;I am facing a problem in forwarding the _internal data to the new indexer.&lt;/P&gt;

&lt;P&gt;my case is I have to forward only _internal data from all the indexers to new indexer servers because in our environment we have dedicated indexer for _internal data.&lt;/P&gt;

&lt;P&gt;when i do this below entry in one of the indexer &lt;BR /&gt;
inputs.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///opt/splunk/idx/splunk/var/log/splunk]
_TCP_ROUTING = management
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;outputs.conf &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
forwardedindex.0.blacklist = .*
forwardedindex.1.whitelist = _internal
forwardedindex.2.whitelist = _audit
forwardedindex.filter.disable = false
disabled=false

[tcpout:management]
server = 10.178.48.66:9997
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This makes all the data to forward from this particular indexer to the new indexer, I need only _internal data to get forwarded. &lt;/P&gt;

&lt;P&gt;I tried using props.conf and transforms.conf too. It's not working. I don't want to store the _internal data in this indexer, it should present only in the new indexers.&lt;BR /&gt;
Kindly need your help.&lt;/P&gt;</description>
    <pubDate>Tue, 20 Feb 2018 10:20:16 GMT</pubDate>
    <dc:creator>benazir</dc:creator>
    <dc:date>2018-02-20T10:20:16Z</dc:date>
    <item>
      <title>How can I forward only _internal index data from indexer to the new indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-only-internal-index-data-from-indexer-to-the/m-p/291912#M55639</link>
      <description>&lt;P&gt;I am facing a problem in forwarding the _internal data to the new indexer.&lt;/P&gt;

&lt;P&gt;my case is I have to forward only _internal data from all the indexers to new indexer servers because in our environment we have dedicated indexer for _internal data.&lt;/P&gt;

&lt;P&gt;when i do this below entry in one of the indexer &lt;BR /&gt;
inputs.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///opt/splunk/idx/splunk/var/log/splunk]
_TCP_ROUTING = management
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;outputs.conf &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
forwardedindex.0.blacklist = .*
forwardedindex.1.whitelist = _internal
forwardedindex.2.whitelist = _audit
forwardedindex.filter.disable = false
disabled=false

[tcpout:management]
server = 10.178.48.66:9997
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This makes all the data to forward from this particular indexer to the new indexer, I need only _internal data to get forwarded. &lt;/P&gt;

&lt;P&gt;I tried using props.conf and transforms.conf too. It's not working. I don't want to store the _internal data in this indexer, it should present only in the new indexers.&lt;BR /&gt;
Kindly need your help.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2018 10:20:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-only-internal-index-data-from-indexer-to-the/m-p/291912#M55639</guid>
      <dc:creator>benazir</dc:creator>
      <dc:date>2018-02-20T10:20:16Z</dc:date>
    </item>
    <item>
      <title>Re: How can I forward only _internal index data from indexer to the new indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-only-internal-index-data-from-indexer-to-the/m-p/291913#M55640</link>
      <description>&lt;P&gt;Is there any reason why a particular indexer set for internal indexes only? This is not the best practice to do so. &lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2018 14:03:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-only-internal-index-data-from-indexer-to-the/m-p/291913#M55640</guid>
      <dc:creator>deepashri_123</dc:creator>
      <dc:date>2018-02-20T14:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: How can I forward only _internal index data from indexer to the new indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-only-internal-index-data-from-indexer-to-the/m-p/291914#M55641</link>
      <description>&lt;P&gt;Try with this outputs.conf (should be etc/apps under some_app/local OR last resort, under etc/system/local)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
indexAndForward = true

[tcpout:management]
server = 10.178.48.66:9997

[indexAndForward]
index=true
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 20 Feb 2018 22:45:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-only-internal-index-data-from-indexer-to-the/m-p/291914#M55641</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-02-20T22:45:20Z</dc:date>
    </item>
    <item>
      <title>Re: How can I forward only _internal index data from indexer to the new indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-only-internal-index-data-from-indexer-to-the/m-p/291915#M55642</link>
      <description>&lt;P&gt;I tried this option, what it does it , it keeps a copy of internal logs here in the old indexers and forward to new indexers too.&lt;/P&gt;

&lt;P&gt;but my case is , I need to see the _internal data of that particular indexers only in the new indexers, not on the source indexer, when I search data from search head for _internal index.. &lt;BR /&gt;
since we have dedicated search heads , for different cluster of indexers. &lt;/P&gt;

&lt;P&gt;Kindly need to your advice, how to just forward, without doing local indexing .&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2018 03:35:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-only-internal-index-data-from-indexer-to-the/m-p/291915#M55642</guid>
      <dc:creator>benazir</dc:creator>
      <dc:date>2018-02-21T03:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: How can I forward only _internal index data from indexer to the new indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-only-internal-index-data-from-indexer-to-the/m-p/291916#M55643</link>
      <description>&lt;P&gt;I haven given the outputs.conf file like below :&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
forwardedindex.0.blacklist = .*&lt;BR /&gt;
forwardedindex.1.whitelist = _internal&lt;BR /&gt;
forwardedindex.2.whitelist = _audit&lt;BR /&gt;
forwardedindex.filter.disable = false&lt;BR /&gt;
disabled=false&lt;BR /&gt;
indexAndForward = true&lt;/P&gt;

&lt;P&gt;[tcpout:management]&lt;BR /&gt;
server = 10.178.48.66:9997&lt;/P&gt;

&lt;P&gt;[indexAndForward]&lt;BR /&gt;
index = true&lt;/P&gt;

&lt;P&gt;Now this is how it works, I cant find any other data forwarded to new management indexer ( that's good) &lt;BR /&gt;
but the problem is _internal data is routed to main index in the new server - 10.178.48.66 and missing few logs like splunkd,metrics all.&lt;BR /&gt;
meantime in the old indexer I am still seeing the data from main as well as _internal  indexes.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2018 04:28:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-only-internal-index-data-from-indexer-to-the/m-p/291916#M55643</guid>
      <dc:creator>benazir</dc:creator>
      <dc:date>2018-02-21T04:28:40Z</dc:date>
    </item>
  </channel>
</rss>

