Deployment Architecture

need to limit what servers are sending logs to an indexer

ralphw_SAIC
Path Finder

We have multiple window SUFs sending logs to a HF that then divide the winevent:security logs between two indexers. One indexer needs to receive logs from all servers, the second indexer needs to receive logs from only particular servers.

Any idea on how i can go about setting this up? I have a custom transform and props configs that will split the event ids between the two indexers, but i need to limit which servers go to the second indexer as well.

Tags (1)
0 Karma

solarboyz1
Builder

On the heavy forwarder:

  1. Create and output group:
    outputs.conf:

    [tcpout:hostGroup]
    server=10.20.30.40:9999

  2. Configure a props entry for the sourcetype in question:

    [sourcetype_to_split]
    TRANSFORMS-index = hostRedirect

  3. Create the output routing transforms.conf:

    [hostRedirect]
    SOURCE_KEY = host
    REGEX = (host1|host2|host3|host4)
    IndexDEST_KEY=_TCP_ROUTING
    FORMAT=hostGroup

0 Karma

ralphw_SAIC
Path Finder

This looks to break things.

Simplifying my setup a bit, IDX-1 receives limited eventIDs for all hosts, IDX-2 receives all eventIDs for a subset of hosts.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...