Deployment Architecture

Prevent forwarder from re forwarding

nicolasbussiere
New Member

We have data being forwarded (heavy forwarder) to a spunk server 1 , and we also forward (heavy forwarder) from that splunk server 1 to an other splunk server 2.

Is there a way to filter out forwarded messages so messages forwarded to server 1 are not sent to server 2 ?

Thanks for any hints !

Tags (2)
0 Karma

renjith_nair
Legend

Do you mean to say splunk server1 is an indexer too?

Anyway try this link to filter or route your data

http://docs.splunk.com/Documentation/Splunk/6.3.1511/Forwarding/Routeandfilterdatad

---
What goes around comes around. If it helps, hit it with Karma 🙂

renjith_nair
Legend

Let me know if it helped!

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...