I have a doubt here..I want to index data to both sandbox and production. What changes do I need to make here.
[tcpout]
defaultGroup = production
[tcpout:sandbox]
server=ABC:PORT
[tcpout:production]
server=XYZ:PORT
autoLB = true
useACK = false
Hi rangineniarunkumar,
just a little additional information:
If this is your need, you should see at http://docs.splunk.com/Documentation/Splunk/6.5.2/Forwarding/Routeandfilterdatad where it's described how to configure your outputs.conf and inputs.conf files.
At first sight I see [default group] stanza in your outputs.conf and you should remove it.
In addition you have to insert in all your inputs.conf files stanzas _TCP_ROUTING = sandbox
or _TCP_ROUTING = production
depending by your logs.
If you want to send the same log to both the indexers you don't need to insert _TCP_ROUTING =
Bye.
Giuseppe
Hi rangineniarunkumar,
just a little additional information:
If this is your need, you should see at http://docs.splunk.com/Documentation/Splunk/6.5.2/Forwarding/Routeandfilterdatad where it's described how to configure your outputs.conf and inputs.conf files.
At first sight I see [default group] stanza in your outputs.conf and you should remove it.
In addition you have to insert in all your inputs.conf files stanzas _TCP_ROUTING = sandbox
or _TCP_ROUTING = production
depending by your logs.
If you want to send the same log to both the indexers you don't need to insert _TCP_ROUTING =
Bye.
Giuseppe