Deployment Architecture

Can you configure a Universal Forwarder output to send to two separate Heavy Forwarders?

Log_wrangler
Builder

I need to send two copies of events to two different HFs (not load-balanced).

I want to use a UF on a server to send events to a HF which will send cooked to the indexers, and I want the UF to send the same events to a different HF that will send raw (uncooked) events to a 3rd party.

Can the UF handle sending the data twice?

Thank you

1 Solution

markusspitzli
Communicator

Hey.

This documentation will help you: https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad

Basically you have to configure two different destinations in outputs.conf:

[tcpout]
defaultGroup=myroute

[tcpout:myroute]
disabled=false
server=10.1.12.1:9997

[tcpout:anotherroute]
disabled=false
server=10.1.12.2:9997

Then you have to configure the props.conf for which sourcetype, host, or source you want to clone the data.

[mysourcetype]
TRANSFORMS-routing = routing

[host::myhost]
TRANSFORMS-routing = routing

[source::/var/log/messages]
TRANSFORMS-routing = routing

Of course you have to configure the transforms.conf

[routing]
REGEX=(.)
DEST_KEY=_TCP_ROUTING
FORMAT=myroute,anotherroute

that should do the job

View solution in original post

0 Karma

markusspitzli
Communicator

Hey.

This documentation will help you: https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad

Basically you have to configure two different destinations in outputs.conf:

[tcpout]
defaultGroup=myroute

[tcpout:myroute]
disabled=false
server=10.1.12.1:9997

[tcpout:anotherroute]
disabled=false
server=10.1.12.2:9997

Then you have to configure the props.conf for which sourcetype, host, or source you want to clone the data.

[mysourcetype]
TRANSFORMS-routing = routing

[host::myhost]
TRANSFORMS-routing = routing

[source::/var/log/messages]
TRANSFORMS-routing = routing

Of course you have to configure the transforms.conf

[routing]
REGEX=(.)
DEST_KEY=_TCP_ROUTING
FORMAT=myroute,anotherroute

that should do the job

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...