Hi Fellow Splunkers,
I am looking to forward all Indexed data from an Indexer Cluster to another third party system. I have read through many posts that suggest configuring a single instance of an Indexer to forward logs cool no problem just follow the guide on "Forward data to third-party systems". However forwarding logs from an Indexer Cluster would be a different ball game right? As different data sits on different indexers in a cluster.
So assuming I have 3 peers that is configured with a Search Factor = 2 and Replication factor of 2. Which Indexer do I choose to forward the logs / what's the best practice? Do I need to add a Heavy Fowarder?
In case this is a one time operation, maybe instead of forwarding the data from index cluster, you can configure the system to read the data off the Splunk deployment, maybe via a REST call. or write a script to read data in small batches with incremental time going back in the past from where you need to start up to current time.
For the incoming data, you can configure a Forwarder to send to this 3rd party system.
Apologies for the late reply. Thanks for the response.
Unfortunately this is not a one time operation. The data has to be continuously piped to the third-party system. There are multiple WAN sites sending data to the indexer via Heavy Forwarders. I have thought of the possibility of configuring all the Heavy Forwarders to send a duplicate to the third party, but this will cause a upsurge in WAN bandwidths which is not ideal at the moment. The scripts are a great idea, I will look into it perhaps scheduling one that reads periodically.
Hey mate, just wondering how you got along with this? im having the same issue at the moment, i have multiple sites and multiple clustered indexers needing to send to one specific indexer.