Deployment Architecture

Configure a new default index on universal forwarder

robinpilch
New Member

I'm currently using a Universal forwarder to forward log data out to a Splunk cloud deployment from internal forwarders, is it possible to configure a custom index on this forwarder so all data goes to the custom index without having to make the change on all internal forwarders?

Tags (1)
0 Karma

FrankVl
Ultra Champion

No, a Universal Forwarder acting as an intermediate forwarder will not be able to route data to another index. It will just pass it along as it received it from the original forwarders.

You will need to configure this either on the original forwarders (which should be fairly straightforward if you manage those with a deployment server), or use a Heavy Forwarder as intermediate, which you then configure with props and transforms to override the index metadata field. Note: the HF solution only works if the original forwarders are UF. For any original forwarder being a HF the config would need to be on that original HF. In general: such configuration needs to be on the first Splunk Enterprise instance that touches the data, so either the first HF, or if no HFs in the path (only UF), then on the Indexer(s).

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...