<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to index mulesoft logs from Main index to another customized index. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-index-mulesoft-logs-from-Main-index-to-another/m-p/366964#M93802</link>
    <description>&lt;P&gt;Now we are getting mulesoft logs to newly created index on indexers but with other sourcetype also like syslogs . So we want to exclude  sourcetype  "syslogs"  from newly created index.&lt;/P&gt;</description>
    <pubDate>Thu, 30 Nov 2017 21:42:40 GMT</pubDate>
    <dc:creator>Swkadam</dc:creator>
    <dc:date>2017-11-30T21:42:40Z</dc:date>
    <item>
      <title>Unable to index mulesoft logs from Main index to another customized index.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-index-mulesoft-logs-from-Main-index-to-another/m-p/366960#M93798</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We have integrated Mulesoft with splunk and logs are sending to the heavy forwarder and indexing into "Main" index  then forwarding to the indexers. &lt;/P&gt;

&lt;P&gt;On Heavy forwarder we have created new index and assigned into the Http collector event but still logs are not indexing into the newly created index.&lt;/P&gt;

&lt;P&gt;So do i need to create same new index on indexers as all indexers are in cluster mode.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Nov 2017 15:37:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-index-mulesoft-logs-from-Main-index-to-another/m-p/366960#M93798</guid>
      <dc:creator>Swkadam</dc:creator>
      <dc:date>2017-11-11T15:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to index mulesoft logs from Main index to another customized index.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-index-mulesoft-logs-from-Main-index-to-another/m-p/366961#M93799</link>
      <description>&lt;P&gt;The issue of the HEC events not being written to the newly created index on the HF is unrelated to the indexing tier. For the sake of clarity, can you confirm that you:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Created a new index&lt;/LI&gt;
&lt;LI&gt;Edited the HEC from Data Inputs and in "Select Allowed Indexes" you removed Main and added your newly created index (i.e. - new_index)&lt;/LI&gt;
&lt;LI&gt;When you search index="new_index" you see no events? You tried running a curl test with the HEC token and there are still no events in there?&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Remember, new created index may not be searched by default based on the index configuration and other RBAC setting.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Nov 2017 20:10:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-index-mulesoft-logs-from-Main-index-to-another/m-p/366961#M93799</guid>
      <dc:creator>ashpatel_splunk</dc:creator>
      <dc:date>2017-11-11T20:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to index mulesoft logs from Main index to another customized index.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-index-mulesoft-logs-from-Main-index-to-another/m-p/366962#M93800</link>
      <description>&lt;P&gt;EDIT: I moved this to a comment: ashpatel's answer is perfectly fine, so now that it's published it, he should get the credit here.  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;  I didn't just delete the below because it could still be useful.&lt;/P&gt;

&lt;P&gt;In fact, I think you need to do two additional things.&lt;/P&gt;

&lt;P&gt;1) Create the index on your indexers.   That's where the data is going, so that's where the indexes the data is going in to need to be.&lt;/P&gt;

&lt;P&gt;2) Also you might need to edit the HTTP Event Collector and change it to allow it to index into that index.  When you created it, if the index where these events are supposed to go you wouldn't have been able to pick it as an allowed index for that HEC to send events to, so you have to go back and reselect that again.&lt;/P&gt;

&lt;P&gt;Then I think it should work.&lt;/P&gt;

&lt;P&gt;Let us know how that goes!&lt;/P&gt;

&lt;P&gt;-Rich&lt;/P&gt;</description>
      <pubDate>Sun, 12 Nov 2017 02:28:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-index-mulesoft-logs-from-Main-index-to-another/m-p/366962#M93800</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2017-11-12T02:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to index mulesoft logs from Main index to another customized index.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-index-mulesoft-logs-from-Main-index-to-another/m-p/366963#M93801</link>
      <description>&lt;P&gt;Thanks for your valuable reply.&lt;/P&gt;

&lt;P&gt;It is working now.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2017 05:27:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-index-mulesoft-logs-from-Main-index-to-another/m-p/366963#M93801</guid>
      <dc:creator>Swkadam</dc:creator>
      <dc:date>2017-11-13T05:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to index mulesoft logs from Main index to another customized index.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-index-mulesoft-logs-from-Main-index-to-another/m-p/366964#M93802</link>
      <description>&lt;P&gt;Now we are getting mulesoft logs to newly created index on indexers but with other sourcetype also like syslogs . So we want to exclude  sourcetype  "syslogs"  from newly created index.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2017 21:42:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-index-mulesoft-logs-from-Main-index-to-another/m-p/366964#M93802</guid>
      <dc:creator>Swkadam</dc:creator>
      <dc:date>2017-11-30T21:42:40Z</dc:date>
    </item>
  </channel>
</rss>

