<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Index internal logs locally and forward all other logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Index-internal-logs-locally-and-forward-all-other-logs/m-p/530945#M89345</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/201643"&gt;@k31453&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe you are looking for below: Note: you can only index _internal logs using this method.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.0/Forwarding/Routeandfilterdatad#Selective_indexing_and_internal_logs" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.0/Forwarding/Routeandfilterdatad#Selective_indexing_and_internal_logs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 26 Nov 2020 06:57:49 GMT</pubDate>
    <dc:creator>thambisetty</dc:creator>
    <dc:date>2020-11-26T06:57:49Z</dc:date>
    <item>
      <title>Index internal logs locally and forward all other logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-internal-logs-locally-and-forward-all-other-logs/m-p/530751#M89314</link>
      <description>&lt;P&gt;As title suggest, i want to index internal logs only and forwards all other logs to forwarders or idxs.&lt;BR /&gt;&lt;BR /&gt;Here is the setup :&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I have one cluster and three indexes setup seperately outside cluster.&lt;/LI&gt;&lt;LI&gt;Cluster has CM, SH and three indexers.&lt;/LI&gt;&lt;LI&gt;Those Three indexers i want to use as Heavy forwarder to send all logs out to external indexes&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Following is default output.conf:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[tcpout]
maxQueueSize = auto
forwardedindex.0.whitelist = .*
forwardedindex.1.blacklist = _.*
forwardedindex.2.whitelist = (_audit|_internal|_introspection|_telemetry|_metrics|_metrics_rollup)
forwardedindex.filter.disable = false
indexAndForward = false&lt;/LI-CODE&gt;&lt;P&gt;Here is what I have done outputs.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[tcpout]
defaultGroup=noforward
disabled=false

[indexAndForward]
index=true
selectiveIndexing=true

[tcpout:forwarders]
server:&amp;lt;forwarders&amp;gt;:9997&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;BR /&gt;Below is my props.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[default]
TRANSFORMS-forwardit = forwardit

[host::*.foo.splunk.com]
TRANSFORMS-routing = indexing&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Below is transforms.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[forwardit]
REGEX = .
DEST_KEY = _TCP_ROUTING
FORMAT = forwarders

[indexing]
REGEX = .
DEST_KEY = _INDEX_AND_FORWARD_ROUTING
FORMAT = local&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;BR /&gt;Essentially all internal indexes should stay within cluster indexes but rest of index or logs forwarded to external indexes.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 04:01:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-internal-logs-locally-and-forward-all-other-logs/m-p/530751#M89314</guid>
      <dc:creator>k31453</dc:creator>
      <dc:date>2020-11-26T04:01:36Z</dc:date>
    </item>
    <item>
      <title>Re: Index internal logs locally and forward other logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-internal-logs-locally-and-forward-all-other-logs/m-p/530758#M89316</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/201643"&gt;@k31453&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Splunk Doc is very much detailed on the question you have asked. check it out using below link.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.0/Forwarding/Routeandfilterdatad#Perform_selective_indexing_and_forwarding" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.0/Forwarding/Routeandfilterdatad#Perform_selective_indexing_and_forwarding&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 06:06:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-internal-logs-locally-and-forward-all-other-logs/m-p/530758#M89316</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-11-25T06:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: Index internal logs locally and forward other logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-internal-logs-locally-and-forward-all-other-logs/m-p/530918#M89341</link>
      <description>&lt;P&gt;Hi, if the intention is to index all internal indexes, i have set&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;&lt;STRONG&gt;_INDEX_AND_FORWARD_ROUTING&lt;/STRONG&gt; and&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;_TCP_ROUTING&lt;/STRONG&gt; which can cause the issue.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 23:57:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-internal-logs-locally-and-forward-all-other-logs/m-p/530918#M89341</guid>
      <dc:creator>k31453</dc:creator>
      <dc:date>2020-11-25T23:57:34Z</dc:date>
    </item>
    <item>
      <title>Re: Index internal logs locally and forward other logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-internal-logs-locally-and-forward-all-other-logs/m-p/530924#M89343</link>
      <description>&lt;P&gt;For me by default i want to forward new indexes created and internal indexes has to be indexed locally. My thoughts is , setup tcpgroup for forwarders and in outputs.conf and inputs.conf i should modify but not sure how.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 00:21:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-internal-logs-locally-and-forward-all-other-logs/m-p/530924#M89343</guid>
      <dc:creator>k31453</dc:creator>
      <dc:date>2020-11-26T00:21:57Z</dc:date>
    </item>
    <item>
      <title>Re: Index internal logs locally and forward all other logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-internal-logs-locally-and-forward-all-other-logs/m-p/530945#M89345</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/201643"&gt;@k31453&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe you are looking for below: Note: you can only index _internal logs using this method.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.0/Forwarding/Routeandfilterdatad#Selective_indexing_and_internal_logs" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.0/Forwarding/Routeandfilterdatad#Selective_indexing_and_internal_logs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 06:57:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-internal-logs-locally-and-forward-all-other-logs/m-p/530945#M89345</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-11-26T06:57:49Z</dc:date>
    </item>
    <item>
      <title>Re: Index internal logs locally and forward all other logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-internal-logs-locally-and-forward-all-other-logs/m-p/531089#M89361</link>
      <description>&lt;P&gt;Well. This tells me i have to use inputs.conf to ensure routing. By default I want to forward logs. But if i see internal logs i will index it and not forward it. This basically is telling me i have to put&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;_INDEX_AND_FORWARD_ROUTING&lt;/STRONG&gt; on all internal inputs.conf this can cause the issue.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 00:48:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-internal-logs-locally-and-forward-all-other-logs/m-p/531089#M89361</guid>
      <dc:creator>k31453</dc:creator>
      <dc:date>2020-11-27T00:48:15Z</dc:date>
    </item>
  </channel>
</rss>

