<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Index override on heavy forwarder data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Index-override-on-heavy-forwarder-data/m-p/319624#M59700</link>
    <description>&lt;P&gt;Hi yu94,&lt;BR /&gt;
Did you tried to override index on indexers? you said that you want to override index only on a set of indexers, so you can:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;take logs using DB Connect on HF setting index1,&lt;/LI&gt;
&lt;LI&gt;then on indexers (only the ones of the selected set), use the index override configuration.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;In this way you can ingest logs on HF with the original index and then modify it on the indexers.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Fri, 20 Oct 2017 11:41:38 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2017-10-20T11:41:38Z</dc:date>
    <item>
      <title>Index override on heavy forwarder data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-override-on-heavy-forwarder-data/m-p/319620#M59696</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;There is situation where we have installed DB connect on HF and then the HF sends that data to 2 sets of different indexers and now we need to override the index name at one set of indexers .&lt;/P&gt;

&lt;P&gt;We have tried to override the index which is coming from UF is working fine.&lt;/P&gt;

&lt;P&gt;When we tried to override the index which is coming from HF (DB Connect), it was not working may be due to the metadata already set by this HF.&lt;/P&gt;

&lt;P&gt;Can you help me to fix this issue?&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Thippesh&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2017 11:03:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-override-on-heavy-forwarder-data/m-p/319620#M59696</guid>
      <dc:creator>yu94</dc:creator>
      <dc:date>2017-10-20T11:03:45Z</dc:date>
    </item>
    <item>
      <title>Re: Index override on heavy forwarder data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-override-on-heavy-forwarder-data/m-p/319621#M59697</link>
      <description>&lt;P&gt;Hi yu94,&lt;BR /&gt;
the easiest way is to override the index name in the set of indexers:&lt;BR /&gt;
on transforms.conf &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[overrideindex]
DEST_KEY =_MetaData:Index
REGEX = .
FORMAT = my_new_index
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;on props.conf &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[mysourcetype]
TRANSFORMS-index = overrideindex
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2017 11:12:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-override-on-heavy-forwarder-data/m-p/319621#M59697</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-10-20T11:12:59Z</dc:date>
    </item>
    <item>
      <title>Re: Index override on heavy forwarder data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-override-on-heavy-forwarder-data/m-p/319622#M59698</link>
      <description>&lt;P&gt;Hi Giuseppe,&lt;/P&gt;

&lt;P&gt;We have tried this. This is not working because the data which generates is HF and we  tried to override at the indexer, so on the HF it is passed the parsing queue and set the metadata file so will not be able to override at the indexer.&lt;/P&gt;

&lt;P&gt;Any other ways of doing it?&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Thippesh&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2017 11:20:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-override-on-heavy-forwarder-data/m-p/319622#M59698</guid>
      <dc:creator>yu94</dc:creator>
      <dc:date>2017-10-20T11:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: Index override on heavy forwarder data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-override-on-heavy-forwarder-data/m-p/319623#M59699</link>
      <description>&lt;P&gt;Since this is a heavy forwarder the data is cooked on this server, therefore the index setting is done here.&lt;/P&gt;

&lt;P&gt;Is it possible to get both sets of indexers to use the same index for this data?&lt;BR /&gt;
If not the transforms.conf might work but you would need to do the transform based on which output was chosen, and I'm unsure how to do that part, also DB Connect can set an index, but it will only set one per input.&lt;/P&gt;

&lt;P&gt;Perhaps you can change your indexers to have the same index name?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2017 11:36:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-override-on-heavy-forwarder-data/m-p/319623#M59699</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2017-10-20T11:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: Index override on heavy forwarder data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-override-on-heavy-forwarder-data/m-p/319624#M59700</link>
      <description>&lt;P&gt;Hi yu94,&lt;BR /&gt;
Did you tried to override index on indexers? you said that you want to override index only on a set of indexers, so you can:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;take logs using DB Connect on HF setting index1,&lt;/LI&gt;
&lt;LI&gt;then on indexers (only the ones of the selected set), use the index override configuration.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;In this way you can ingest logs on HF with the original index and then modify it on the indexers.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2017 11:41:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-override-on-heavy-forwarder-data/m-p/319624#M59700</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-10-20T11:41:38Z</dc:date>
    </item>
  </channel>
</rss>

