Deployment Architecture

Setting outputs.conf

rangineniarunku
Explorer

I have a doubt here..I want to index data to both sandbox and production. What changes do I need to make here.

[tcpout]
defaultGroup = production

[tcpout:sandbox]
server=ABC:PORT

[tcpout:production]
server=XYZ:PORT
autoLB = true
useACK = false

Tags (1)
0 Karma
1 Solution

gcusello
Esteemed Legend

Hi rangineniarunkumar,
just a little additional information:

  • are sandbox and production indexers?
  • do you want to send some logs to sandbox and some logs to production?

If this is your need, you should see at http://docs.splunk.com/Documentation/Splunk/6.5.2/Forwarding/Routeandfilterdatad where it's described how to configure your outputs.conf and inputs.conf files.

At first sight I see [default group] stanza in your outputs.conf and you should remove it.
In addition you have to insert in all your inputs.conf files stanzas _TCP_ROUTING = sandbox or _TCP_ROUTING = production depending by your logs.
If you want to send the same log to both the indexers you don't need to insert _TCP_ROUTING =

Bye.
Giuseppe

View solution in original post

gcusello
Esteemed Legend

Hi rangineniarunkumar,
just a little additional information:

  • are sandbox and production indexers?
  • do you want to send some logs to sandbox and some logs to production?

If this is your need, you should see at http://docs.splunk.com/Documentation/Splunk/6.5.2/Forwarding/Routeandfilterdatad where it's described how to configure your outputs.conf and inputs.conf files.

At first sight I see [default group] stanza in your outputs.conf and you should remove it.
In addition you have to insert in all your inputs.conf files stanzas _TCP_ROUTING = sandbox or _TCP_ROUTING = production depending by your logs.
If you want to send the same log to both the indexers you don't need to insert _TCP_ROUTING =

Bye.
Giuseppe

Get Updates on the Splunk Community!

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...

.conf23 Registration is Now Open!

Time to toss the .conf-etti 🎉 —  .conf23 registration is open!   Join us in Las Vegas July 17-20 for ...