<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ingesting data into two indexes from one Heavy Forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Ingesting-data-into-two-indexes-from-one-Heavy-Forwarder/m-p/551878#M91593</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234489"&gt;@splunky1&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;each Heavy Forwarder (don't ask me why because I never understood this!) sends logs to only one Indexer even if it has two Indexers available: it can change the destination Indexer, but always one at a time.&lt;/P&gt;&lt;P&gt;If you can is more efficient to use the Heavy Forwarder as a concentrator only if you have strickly security requirements, in other words, if you can is more efficient that UFs send their logs directly to the Indexers and use HF only for syslogs.&lt;/P&gt;&lt;P&gt;In addition if you have only one HF you have an additional Single Point of failure&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 17 May 2021 14:09:22 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2021-05-17T14:09:22Z</dc:date>
    <item>
      <title>Ingesting data into two indexes from one Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Ingesting-data-into-two-indexes-from-one-Heavy-Forwarder/m-p/551875#M91592</link>
      <description>&lt;P&gt;I have Splunk in the below design&lt;/P&gt;&lt;P&gt;One HF to two sperate indexers that are not clustered.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have UF installed on my workstation and UF is sending logs to the HF.&lt;/P&gt;&lt;P&gt;HF has data inputs set to all types of windows logs to an index to windows and this is going to indexer A but data not going to indexer B.&lt;/P&gt;&lt;P&gt;My outputs.conf in the UF is like&lt;/P&gt;&lt;P&gt;[tcpout]&lt;BR /&gt;useACK = true&lt;BR /&gt;maxQueueSize = auto&lt;BR /&gt;readTimeout = 300&lt;/P&gt;&lt;P&gt;[tcpout:abchf]&lt;BR /&gt;server = 10.20.30.40:9997&lt;BR /&gt;compressed = TRUE&lt;BR /&gt;sslRootCAPath = C:/Program Files/SplunkUniversalForwarder/etc/apps/test&lt;BR /&gt;sslCertPath = C:/Program Files/SplunkUniversalForwarder/etc/apps/test&lt;BR /&gt;sslPassword = Password&lt;BR /&gt;sslVerifyServerCert = true&lt;BR /&gt;sslCommonNameToCheck = google.com&lt;/P&gt;&lt;P&gt;In the indexer A I can see the data is ingested but in the indexer B I cannot see the data.&lt;/P&gt;&lt;P&gt;As I mentioned earlier indexer A and indexer B are not clustered indexers.&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 13:18:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Ingesting-data-into-two-indexes-from-one-Heavy-Forwarder/m-p/551875#M91592</guid>
      <dc:creator>splunky1</dc:creator>
      <dc:date>2021-05-17T13:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: Ingesting data into two indexes from one Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Ingesting-data-into-two-indexes-from-one-Heavy-Forwarder/m-p/551878#M91593</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234489"&gt;@splunky1&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;each Heavy Forwarder (don't ask me why because I never understood this!) sends logs to only one Indexer even if it has two Indexers available: it can change the destination Indexer, but always one at a time.&lt;/P&gt;&lt;P&gt;If you can is more efficient to use the Heavy Forwarder as a concentrator only if you have strickly security requirements, in other words, if you can is more efficient that UFs send their logs directly to the Indexers and use HF only for syslogs.&lt;/P&gt;&lt;P&gt;In addition if you have only one HF you have an additional Single Point of failure&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 14:09:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Ingesting-data-into-two-indexes-from-one-Heavy-Forwarder/m-p/551878#M91593</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-05-17T14:09:22Z</dc:date>
    </item>
  </channel>
</rss>

