<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data Redirection Issue in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Data-Redirection-Issue/m-p/397500#M8809</link>
    <description>&lt;P&gt;Hi @daniel333 ,&lt;/P&gt;

&lt;P&gt;Could you please share the &lt;CODE&gt;outputs.conf&lt;/CODE&gt; stanza you have currently?&lt;/P&gt;

&lt;P&gt;Thank You.&lt;/P&gt;</description>
    <pubDate>Sat, 12 Jan 2019 05:25:39 GMT</pubDate>
    <dc:creator>MousumiChowdhur</dc:creator>
    <dc:date>2019-01-12T05:25:39Z</dc:date>
    <item>
      <title>Data Redirection Issue</title>
      <link>https://community.splunk.com/t5/Installation/Data-Redirection-Issue/m-p/397498#M8807</link>
      <description>&lt;P&gt;All, &lt;/P&gt;

&lt;P&gt;I am getting logs into an existing Splunk installation with &lt;BR /&gt;
index=wrong sourcetype=wayoutofdate&lt;/P&gt;

&lt;P&gt;that data needs to continue as is. There are users counting on those logs as they are . I'd like to send a second copy of these logs to a new set of indexers with &lt;BR /&gt;
index=correct sourcetype=correctsourctype&lt;/P&gt;

&lt;P&gt;I am not sure how to make the three transform changes without breaking what already exists off my heavy forwarders. Any help?&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jan 2019 02:02:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Data-Redirection-Issue/m-p/397498#M8807</guid>
      <dc:creator>daniel333</dc:creator>
      <dc:date>2019-01-12T02:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: Data Redirection Issue</title>
      <link>https://community.splunk.com/t5/Installation/Data-Redirection-Issue/m-p/397499#M8808</link>
      <description>&lt;P&gt;The easiest way is to create a symlink to the directory where the files are now ( &lt;CODE&gt;ln -s current_directory symlink_directory&lt;/CODE&gt; ) and put a second monitor stanza pointed at the new directory.  The downside is double the work on the forwarder and double the license cost.&lt;/P&gt;

&lt;P&gt;The other way, which is extremely fragile and also creates much latency but has no license cost, is to use copy it into a &lt;CODE&gt;summary index&lt;/CODE&gt; with a populating search that is scheduled to run all the time.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jan 2019 05:23:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Data-Redirection-Issue/m-p/397499#M8808</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-12T05:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: Data Redirection Issue</title>
      <link>https://community.splunk.com/t5/Installation/Data-Redirection-Issue/m-p/397500#M8809</link>
      <description>&lt;P&gt;Hi @daniel333 ,&lt;/P&gt;

&lt;P&gt;Could you please share the &lt;CODE&gt;outputs.conf&lt;/CODE&gt; stanza you have currently?&lt;/P&gt;

&lt;P&gt;Thank You.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jan 2019 05:25:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Data-Redirection-Issue/m-p/397500#M8809</guid>
      <dc:creator>MousumiChowdhur</dc:creator>
      <dc:date>2019-01-12T05:25:39Z</dc:date>
    </item>
    <item>
      <title>Re: Data Redirection Issue</title>
      <link>https://community.splunk.com/t5/Installation/Data-Redirection-Issue/m-p/397501#M8810</link>
      <description>&lt;P&gt;You should be able to trivially clone the data into the right index/sourcetype and much much more using &lt;A href="http://cribl.io"&gt;Cribl&lt;/A&gt; - check out this &lt;A href="https://blog.cribl.io/2018/10/24/routing-full-fidelity-and-sampling-data-with-cribl/"&gt;blog post&lt;/A&gt; for an example of how to clone data.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Jan 2019 05:39:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Data-Redirection-Issue/m-p/397501#M8810</guid>
      <dc:creator>ledion</dc:creator>
      <dc:date>2019-01-13T05:39:46Z</dc:date>
    </item>
  </channel>
</rss>

