Deployment Architecture

Rotuing data to specific indexes

aab5272
Engager

I have situtationn where i have cluster master which managed the indexer cluster . I am getiing data in load balancing way based on autoLBfrequency . Now i want to route data at a particular index , do iahve to make change in props.conf and tansform.conf at the master or at each peer indexer ?

Tags (1)
0 Karma
1 Solution

WalshyB
Path Finder

On the Cluster Master, the app is in /etc/master-apps right?

Change the props, transforms in the relevant app and then push the cluster bundle - ./splunk apply cluster-bundle

This will push the new bundle to the cluster members. If you need information on the filtering, please let me know

Example on filtering:
within transforms

[index_filter_example]
REGEX = regex for what you want to match
FORMAT = index name
DEST_KEY = _MetaData:Index

within props
[sourcetype]
TRANSFORMS-index_filters = index_filter_example, .....

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi aab5272,
sorry but I don't understand yyour need: are you speaking about forwarding data to indexers and do you want to send data to a clustered index?
in this case you have only to specify index in your inputs.conf file on forwarders.

If instead you want to send logs to a non clustered index that is present in only one Indexer, you have to use selective indexing (see http://docs.splunk.com/Documentation/Splunk/6.6.1/Forwarding/Routeandfilterdatad).

Bye.
Giuseppe

0 Karma

aab5272
Engager

yes My cluster is indexer cluster . and other question is that how does splunk handle creation of indexes?
like ket say i have multisite indexer cluster where would i create index ?

0 Karma

gcusello
SplunkTrust
SplunkTrust

In indexers cluster, indexes are created on the master node, otherwise they aren't replicated.
Bye.
Giuseppe

0 Karma

WalshyB
Path Finder

On the Cluster Master, the app is in /etc/master-apps right?

Change the props, transforms in the relevant app and then push the cluster bundle - ./splunk apply cluster-bundle

This will push the new bundle to the cluster members. If you need information on the filtering, please let me know

Example on filtering:
within transforms

[index_filter_example]
REGEX = regex for what you want to match
FORMAT = index name
DEST_KEY = _MetaData:Index

within props
[sourcetype]
TRANSFORMS-index_filters = index_filter_example, .....

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...