Deployment Architecture

Rotuing data to specific indexes

aab5272
Engager

I have situtationn where i have cluster master which managed the indexer cluster . I am getiing data in load balancing way based on autoLBfrequency . Now i want to route data at a particular index , do iahve to make change in props.conf and tansform.conf at the master or at each peer indexer ?

Tags (1)
0 Karma
1 Solution

WalshyB
Path Finder

On the Cluster Master, the app is in /etc/master-apps right?

Change the props, transforms in the relevant app and then push the cluster bundle - ./splunk apply cluster-bundle

This will push the new bundle to the cluster members. If you need information on the filtering, please let me know

Example on filtering:
within transforms

[index_filter_example]
REGEX = regex for what you want to match
FORMAT = index name
DEST_KEY = _MetaData:Index

within props
[sourcetype]
TRANSFORMS-index_filters = index_filter_example, .....

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi aab5272,
sorry but I don't understand yyour need: are you speaking about forwarding data to indexers and do you want to send data to a clustered index?
in this case you have only to specify index in your inputs.conf file on forwarders.

If instead you want to send logs to a non clustered index that is present in only one Indexer, you have to use selective indexing (see http://docs.splunk.com/Documentation/Splunk/6.6.1/Forwarding/Routeandfilterdatad).

Bye.
Giuseppe

0 Karma

aab5272
Engager

yes My cluster is indexer cluster . and other question is that how does splunk handle creation of indexes?
like ket say i have multisite indexer cluster where would i create index ?

0 Karma

gcusello
SplunkTrust
SplunkTrust

In indexers cluster, indexes are created on the master node, otherwise they aren't replicated.
Bye.
Giuseppe

0 Karma

WalshyB
Path Finder

On the Cluster Master, the app is in /etc/master-apps right?

Change the props, transforms in the relevant app and then push the cluster bundle - ./splunk apply cluster-bundle

This will push the new bundle to the cluster members. If you need information on the filtering, please let me know

Example on filtering:
within transforms

[index_filter_example]
REGEX = regex for what you want to match
FORMAT = index name
DEST_KEY = _MetaData:Index

within props
[sourcetype]
TRANSFORMS-index_filters = index_filter_example, .....

0 Karma
Get Updates on the Splunk Community!

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...

Stay Connected: Your Guide to October Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...