<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Route data on Heavy Forwarder is not working in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Route-data-on-Heavy-Forwarder-is-not-working/m-p/397436#M70849</link>
    <description>&lt;P&gt;I checked my transforms.conf and the two _TCP_ROUTING are from my [index01] and [index02] stanzas&lt;/P&gt;

&lt;P&gt;And on my props.conf I can see my transformation applied.&lt;/P&gt;

&lt;P&gt;/opt/splunk/etc/apps/hf/local/props.conf                          [browser]&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         ANNOTATE_PUNCT = True&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         AUTO_KV_JSON = true&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         BREAK_ONLY_BEFORE = &lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         BREAK_ONLY_BEFORE_DATE = True&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         CHARSET = UTF-8&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         DATETIME_CONFIG = /etc/datetime.xml&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         HEADER_MODE = &lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         LEARN_MODEL = true&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         LEARN_SOURCETYPE = true&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         LINE_BREAKER_LOOKBEHIND = 100&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         MATCH_LIMIT = 100000&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         MAX_DAYS_AGO = 2000&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         MAX_DAYS_HENCE = 2&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         MAX_DIFF_SECS_AGO = 3600&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         MAX_DIFF_SECS_HENCE = 604800&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         MAX_EVENTS = 256&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         MAX_TIMESTAMP_LOOKAHEAD = 128&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         MUST_BREAK_AFTER = &lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         MUST_NOT_BREAK_AFTER = &lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         MUST_NOT_BREAK_BEFORE = &lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         SEGMENTATION = indexing&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         SEGMENTATION-all = full&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         SEGMENTATION-inner = inner&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         SEGMENTATION-outer = outer&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         SEGMENTATION-raw = none&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         SEGMENTATION-standard = standard&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         SHOULD_LINEMERGE = True&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         TRANSFORMS = &lt;BR /&gt;
/opt/splunk/etc/apps/hf/local/props.conf                          TRANSFORMS-routing = index02&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         TRUNCATE = 10000&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         detect_trailing_nulls = false&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         maxDist = 100&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         priority = &lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         sourcetype = &lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 19:32:07 GMT</pubDate>
    <dc:creator>lit_gustavo</dc:creator>
    <dc:date>2020-09-29T19:32:07Z</dc:date>
    <item>
      <title>Route data on Heavy Forwarder is not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Route-data-on-Heavy-Forwarder-is-not-working/m-p/397432#M70845</link>
      <description>&lt;P&gt;Hi guys I tried hard here and read some docs:&lt;BR /&gt;
(&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.1.0/Admin/Inputsconf"&gt;https://docs.splunk.com/Documentation/Splunk/7.1.0/Admin/Inputsconf&lt;/A&gt;)&lt;BR /&gt;
(&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.1.0/Admin/Propsconf"&gt;https://docs.splunk.com/Documentation/Splunk/7.1.0/Admin/Propsconf&lt;/A&gt;)&lt;BR /&gt;
(&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.1.0/Admin/Transformsconf"&gt;https://docs.splunk.com/Documentation/Splunk/7.1.0/Admin/Transformsconf&lt;/A&gt;)&lt;BR /&gt;
(&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.1.0/Admin/Outputsconf"&gt;https://docs.splunk.com/Documentation/Splunk/7.1.0/Admin/Outputsconf&lt;/A&gt;)&lt;BR /&gt;
(&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.1.0/Forwarding/Forwarddatatothird-partysystemsd"&gt;https://docs.splunk.com/Documentation/Splunk/7.1.0/Forwarding/Forwarddatatothird-partysystemsd&lt;/A&gt;)&lt;BR /&gt;
(&lt;A href="https://answers.splunk.com/answers/474297/how-to-route-and-filter-data-on-the-heavy-forwarde.html?utm_source=typeahead&amp;amp;utm_medium=newquestion&amp;amp;utm_campaign=no_votes_sort_relev"&gt;https://answers.splunk.com/answers/474297/how-to-route-and-filter-data-on-the-heavy-forwarde.html?utm_source=typeahead&amp;amp;utm_medium=newquestion&amp;amp;utm_campaign=no_votes_sort_relev&lt;/A&gt;)&lt;/P&gt;

&lt;P&gt;But I don´t know what I am doing wrong. I just have to send data to different indexers, but my Heavy Forwarder is clonning the data (I need some of data on indexer01 and the other on indexer02).&lt;/P&gt;

&lt;P&gt;Here is my inputs.conf (all configs on my Heavy Forwarder)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[splunktcp://9997]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Here is my props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[host::SRVPRD0001]
TRANSFORMS-routing = index01

[host::SRVPRD0002]
TRANSFORMS-routing = index02

[host::SRVPRD0003]
TRANSFORMS-routing = index02

[host::SRVPRD0004]
TRANSFORMS-routing = index02

[host::SRVPRD0005]
TRANSFORMS-routing = index02
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Here my transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[index01]
REGEX= .
DEST_KEY=_TCP_ROUTING
FORMAT=sendtoidx01

[index02]
REGEX= .
DEST_KEY=_TCP_ROUTING
FORMAT=sendtoidx02
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Here my outputs.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[default]
indexAndForward=false

[tcpout:sendtoidx01]
disabled=false
server=192.168.1.73:9997

[tcpout:sendtoidx02]
disabled=false
server=192.168.1.72:9997
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 14 May 2018 02:11:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Route-data-on-Heavy-Forwarder-is-not-working/m-p/397432#M70845</guid>
      <dc:creator>lit_gustavo</dc:creator>
      <dc:date>2018-05-14T02:11:39Z</dc:date>
    </item>
    <item>
      <title>Re: Route data on Heavy Forwarder is not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Route-data-on-Heavy-Forwarder-is-not-working/m-p/397433#M70846</link>
      <description>&lt;P&gt;Any chance that your props stanzas don't match? Everything else looks fine to me...&lt;/P&gt;</description>
      <pubDate>Mon, 14 May 2018 08:29:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Route-data-on-Heavy-Forwarder-is-not-working/m-p/397433#M70846</guid>
      <dc:creator>xpac</dc:creator>
      <dc:date>2018-05-14T08:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: Route data on Heavy Forwarder is not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Route-data-on-Heavy-Forwarder-is-not-working/m-p/397434#M70847</link>
      <description>&lt;P&gt;Hi xpac, I changed the stanza on my props.conf to &lt;A href="https://community.splunk.com/the%20data%20sourcetype"&gt;browser&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;[browser]&lt;BR /&gt;
TRANSFORMS-routing = index02&lt;/P&gt;

&lt;P&gt;That way all data should flow only to index02, however my heavy forwarder still splits the data.&lt;/P&gt;</description>
      <pubDate>Mon, 14 May 2018 13:59:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Route-data-on-Heavy-Forwarder-is-not-working/m-p/397434#M70847</guid>
      <dc:creator>lit_gustavo</dc:creator>
      <dc:date>2018-05-14T13:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: Route data on Heavy Forwarder is not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Route-data-on-Heavy-Forwarder-is-not-working/m-p/397435#M70848</link>
      <description>&lt;P&gt;Mhh, I'd try a &lt;CODE&gt;splunk btool props list&lt;/CODE&gt; or &lt;CODE&gt;splunk show config props&lt;/CODE&gt;to see if the config is actually applied, or if anything is applied after those transforms that might reset the _TCP_ROUTING variable...&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:28:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Route-data-on-Heavy-Forwarder-is-not-working/m-p/397435#M70848</guid>
      <dc:creator>xpac</dc:creator>
      <dc:date>2020-09-29T19:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: Route data on Heavy Forwarder is not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Route-data-on-Heavy-Forwarder-is-not-working/m-p/397436#M70849</link>
      <description>&lt;P&gt;I checked my transforms.conf and the two _TCP_ROUTING are from my [index01] and [index02] stanzas&lt;/P&gt;

&lt;P&gt;And on my props.conf I can see my transformation applied.&lt;/P&gt;

&lt;P&gt;/opt/splunk/etc/apps/hf/local/props.conf                          [browser]&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         ANNOTATE_PUNCT = True&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         AUTO_KV_JSON = true&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         BREAK_ONLY_BEFORE = &lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         BREAK_ONLY_BEFORE_DATE = True&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         CHARSET = UTF-8&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         DATETIME_CONFIG = /etc/datetime.xml&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         HEADER_MODE = &lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         LEARN_MODEL = true&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         LEARN_SOURCETYPE = true&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         LINE_BREAKER_LOOKBEHIND = 100&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         MATCH_LIMIT = 100000&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         MAX_DAYS_AGO = 2000&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         MAX_DAYS_HENCE = 2&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         MAX_DIFF_SECS_AGO = 3600&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         MAX_DIFF_SECS_HENCE = 604800&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         MAX_EVENTS = 256&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         MAX_TIMESTAMP_LOOKAHEAD = 128&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         MUST_BREAK_AFTER = &lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         MUST_NOT_BREAK_AFTER = &lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         MUST_NOT_BREAK_BEFORE = &lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         SEGMENTATION = indexing&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         SEGMENTATION-all = full&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         SEGMENTATION-inner = inner&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         SEGMENTATION-outer = outer&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         SEGMENTATION-raw = none&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         SEGMENTATION-standard = standard&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         SHOULD_LINEMERGE = True&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         TRANSFORMS = &lt;BR /&gt;
/opt/splunk/etc/apps/hf/local/props.conf                          TRANSFORMS-routing = index02&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         TRUNCATE = 10000&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         detect_trailing_nulls = false&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         maxDist = 100&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         priority = &lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                         sourcetype = &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:32:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Route-data-on-Heavy-Forwarder-is-not-working/m-p/397436#M70849</guid>
      <dc:creator>lit_gustavo</dc:creator>
      <dc:date>2020-09-29T19:32:07Z</dc:date>
    </item>
  </channel>
</rss>

