All Apps and Add-ons

Data not forwarded to Indexer without a local index

mnaim
Explorer

I'm currently sending REST API Modular Input data to a Heavy Forwarder, which is supposed to forward the data to the Indexer. Data is forwarded to the Indexer only when I index it on the Heavy Forwarder first. I don't want to index on the forwarder. I just want the data to get forwarded to the Indexer.

Any idea what could be the issue?

Thank you,

0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

While you can create inputs on the inputs.conf or any index you want.
You cannot create an input using CLI/REST without the index destination being defined locally (It is because of a test check that is not relevant to the forwarders.).

This is fixed in splunk 6.*
Otherwise for splunk 5 or 4, the workaround is to use the configuration file, or define the index first (event if events are forwarded not indexed locally) see http://answers.splunk.com//answers/104473/forwarding-events-to-custom-index-on-cluster-peers

View solution in original post

0 Karma

yannK
Splunk Employee
Splunk Employee

While you can create inputs on the inputs.conf or any index you want.
You cannot create an input using CLI/REST without the index destination being defined locally (It is because of a test check that is not relevant to the forwarders.).

This is fixed in splunk 6.*
Otherwise for splunk 5 or 4, the workaround is to use the configuration file, or define the index first (event if events are forwarded not indexed locally) see http://answers.splunk.com//answers/104473/forwarding-events-to-custom-index-on-cluster-peers

0 Karma

mnaim
Explorer

Thank you!

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...