Deployment Architecture

How to deploy Splunk HF to two indexers?

siuolkl
Explorer

hi experts

trying to deploy a HF and forward logs to 2 different indexers. clone data
i have 2 UFs feeding windows and syslog logs respectively to a HF.

This is my HF output conf, i think there some thing wrong here as i can only see logs at my indexer1

[tcpout]
defaultGroup=windows,syslog
[tcpout:windows,syslog]
server=indexer1 ip:9997

[tcpout:windows,syslog]
server=indexer2 ip:9997

appreciate any help.

 

siuolkl_0-1666083250996.png

 

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @siuolkl,

don't use default group:

[tcpout]

[tcpout:ABC_1]
server=indexer1_ip:9997

[tcpout:ABC_2]
server=indexer2;ip:9997

remember that the group names in the stanza headers (tcpout:...) must be different not the same.

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @siuolkl,

don't use default group:

[tcpout]

[tcpout:ABC_1]
server=indexer1_ip:9997

[tcpout:ABC_2]
server=indexer2;ip:9997

remember that the group names in the stanza headers (tcpout:...) must be different not the same.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @siuolkl,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...