Is it possible to forward different Splunk Add-on for AWS inputs to different indexer clusters? We have a heavy forwarder using Splunk_TA_aws and standard defaultGroup=<clusterlabel>, indexerDiscovery, etc configured in etc/system/local/outputs.conf. At present, all the AWS inputs are forwarded to indexes contained within the default indexer cluster. However, we now have an AWS input which we want to forward to an index in a different indexer cluster. Are there options within either the etc/apps/Splunk_TA_aws/local/ or other .conf files that will allow us to, say, add a second [tcpout:Cluster2] stanza into outputs.conf and then forward events from this new AWS input to it?
I didn't try your solution, but another colleague got it working with the following configuration.
../etc/system/local/outputs.conf [indexer_discovery:first_cluster_label] master_uri = https://mm.mm.mm.mm:8089 passSymmKey = $asdfasfasdfasfasdfasdfas= . . . [indexer_discovery:second_cluster_label] master_uri = https://nn.nn.nn.nn:8089 passSymmKey = $zxcvzxcvzxcvzxcvzxcvzxcv= . . . [tcpout:FirstClusterName] autoLBFrequency = 30 indexerDiscovery = first_cluster_label . . . [tcpout:SecondClusterName] autoLBFrequency = 30 indexerDiscovery = second_cluster_label . . . [tcpout] defaultGroup = FirstClusterName . . . ../etc/apps/Splunk_TA_aws/inputs.conf [aws_sqs_based_s3://First_SQS_S3_Import] # Uses defaultGroup. . . . [aws_sqs_based_s3://Second_SQS_S3_Import] _TCP_ROUTING = SecondClusterName . . .