<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Understand which HF send data to whic index in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Understand-which-HF-send-data-to-whic-index/m-p/691553#M235464</link>
    <description>&lt;P&gt;Hi Splunkers, currently we are managing an Enterprise Splunk environment previously managed by another company. As sadly often occurs, no documentation has been released and so we had to discover almost information about architecture by ourselves. We successfully managed many tasks related to this big problem, but few ones remain; in particular, the one for what I open this discussion.&lt;/P&gt;&lt;P&gt;The point is this: almost total ingested data are collected flowing to a couple of HF. This means that data flow is, typically:&lt;/P&gt;&lt;P&gt;Log sources -&amp;gt; On prem HF -&amp;gt; Cloud HF (on IaaS VM) -&amp;gt; Cloud Indexer (on IaaS VM).&lt;/P&gt;&lt;P&gt;With a search discovered here on community, based on internal logs, I found how to understand what Splunk component send data to another Splunk one. I mean: suppose I have&lt;/P&gt;&lt;P&gt;HF on prem 1 -&amp;gt; Hf on cloud 2&lt;/P&gt;&lt;P&gt;I know how to discover this analyzing the internal logs. But what about if I want to discover which HF on prem collect data sent to a specific index? Let me do an example. Suppose I have this host set:&lt;/P&gt;&lt;P&gt;Log sources (with NO UF installed on them)&lt;/P&gt;&lt;P&gt;Log source 1&lt;BR /&gt;Log source 2&lt;BR /&gt;Log source 3&lt;/P&gt;&lt;P&gt;On prem HF&lt;/P&gt;&lt;P&gt;HF on prem 1&lt;BR /&gt;HF on prem 2&lt;BR /&gt;HF on prem 3&lt;/P&gt;&lt;P&gt;On cloud HF (IaaS VM)&lt;/P&gt;&lt;P&gt;HF on Cloud 1&lt;/P&gt;&lt;P&gt;On cloud indexer&lt;/P&gt;&lt;P&gt;Indexer on cloud 1 (IaaS VM)&lt;/P&gt;&lt;P&gt;Indexes&lt;/P&gt;&lt;P&gt;index1&lt;BR /&gt;index2&lt;BR /&gt;index3&lt;/P&gt;&lt;P&gt;At starting point, I know only that all 3 On prem HF collect data and send them to HF on Cloud: then, data are sent to the Indexer. I don’t know which On prem HF collect data from which Log source, and in which index data are collected once they arrive on indexer; for sure, I could ask to system owner what configuration has been performed on log sources, but the idea is to discover this with a Splunk Search. Is this possible?&lt;/P&gt;&lt;P&gt;The idea is to have a search where I can specify the exact flow. For example, suppose that 1 of the above flow is:&lt;BR /&gt;&lt;BR /&gt;Log source 1 -&amp;gt; On Prem HF 2 -&amp;gt; On Cloud HF -&amp;gt; On Cloud Indexer -&amp;gt; index3&lt;/P&gt;&lt;P&gt;I must be able to discover it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jun 2024 12:13:25 GMT</pubDate>
    <dc:creator>SplunkExplorer</dc:creator>
    <dc:date>2024-06-25T12:13:25Z</dc:date>
    <item>
      <title>Understand which HF send data to whic index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Understand-which-HF-send-data-to-whic-index/m-p/691553#M235464</link>
      <description>&lt;P&gt;Hi Splunkers, currently we are managing an Enterprise Splunk environment previously managed by another company. As sadly often occurs, no documentation has been released and so we had to discover almost information about architecture by ourselves. We successfully managed many tasks related to this big problem, but few ones remain; in particular, the one for what I open this discussion.&lt;/P&gt;&lt;P&gt;The point is this: almost total ingested data are collected flowing to a couple of HF. This means that data flow is, typically:&lt;/P&gt;&lt;P&gt;Log sources -&amp;gt; On prem HF -&amp;gt; Cloud HF (on IaaS VM) -&amp;gt; Cloud Indexer (on IaaS VM).&lt;/P&gt;&lt;P&gt;With a search discovered here on community, based on internal logs, I found how to understand what Splunk component send data to another Splunk one. I mean: suppose I have&lt;/P&gt;&lt;P&gt;HF on prem 1 -&amp;gt; Hf on cloud 2&lt;/P&gt;&lt;P&gt;I know how to discover this analyzing the internal logs. But what about if I want to discover which HF on prem collect data sent to a specific index? Let me do an example. Suppose I have this host set:&lt;/P&gt;&lt;P&gt;Log sources (with NO UF installed on them)&lt;/P&gt;&lt;P&gt;Log source 1&lt;BR /&gt;Log source 2&lt;BR /&gt;Log source 3&lt;/P&gt;&lt;P&gt;On prem HF&lt;/P&gt;&lt;P&gt;HF on prem 1&lt;BR /&gt;HF on prem 2&lt;BR /&gt;HF on prem 3&lt;/P&gt;&lt;P&gt;On cloud HF (IaaS VM)&lt;/P&gt;&lt;P&gt;HF on Cloud 1&lt;/P&gt;&lt;P&gt;On cloud indexer&lt;/P&gt;&lt;P&gt;Indexer on cloud 1 (IaaS VM)&lt;/P&gt;&lt;P&gt;Indexes&lt;/P&gt;&lt;P&gt;index1&lt;BR /&gt;index2&lt;BR /&gt;index3&lt;/P&gt;&lt;P&gt;At starting point, I know only that all 3 On prem HF collect data and send them to HF on Cloud: then, data are sent to the Indexer. I don’t know which On prem HF collect data from which Log source, and in which index data are collected once they arrive on indexer; for sure, I could ask to system owner what configuration has been performed on log sources, but the idea is to discover this with a Splunk Search. Is this possible?&lt;/P&gt;&lt;P&gt;The idea is to have a search where I can specify the exact flow. For example, suppose that 1 of the above flow is:&lt;BR /&gt;&lt;BR /&gt;Log source 1 -&amp;gt; On Prem HF 2 -&amp;gt; On Cloud HF -&amp;gt; On Cloud Indexer -&amp;gt; index3&lt;/P&gt;&lt;P&gt;I must be able to discover it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2024 12:13:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Understand-which-HF-send-data-to-whic-index/m-p/691553#M235464</guid>
      <dc:creator>SplunkExplorer</dc:creator>
      <dc:date>2024-06-25T12:13:25Z</dc:date>
    </item>
    <item>
      <title>Re: Understand which HF send data to whic index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Understand-which-HF-send-data-to-whic-index/m-p/691605#M235481</link>
      <description>&lt;P&gt;HFs process data transparently so there's no way to track the flow of events.&amp;nbsp; Many customers work around that by having the HF add a field to every event where the value of the field is the HF's name.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2024 19:06:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Understand-which-HF-send-data-to-whic-index/m-p/691605#M235481</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-06-25T19:06:26Z</dc:date>
    </item>
  </channel>
</rss>

