Deployment Architecture

need to limit what servers are sending logs to an indexer

ralphw_SAIC
Path Finder

We have multiple window SUFs sending logs to a HF that then divide the winevent:security logs between two indexers. One indexer needs to receive logs from all servers, the second indexer needs to receive logs from only particular servers.

Any idea on how i can go about setting this up? I have a custom transform and props configs that will split the event ids between the two indexers, but i need to limit which servers go to the second indexer as well.

Tags (1)
0 Karma

solarboyz1
Builder

On the heavy forwarder:

  1. Create and output group:
    outputs.conf:

    [tcpout:hostGroup]
    server=10.20.30.40:9999

  2. Configure a props entry for the sourcetype in question:

    [sourcetype_to_split]
    TRANSFORMS-index = hostRedirect

  3. Create the output routing transforms.conf:

    [hostRedirect]
    SOURCE_KEY = host
    REGEX = (host1|host2|host3|host4)
    IndexDEST_KEY=_TCP_ROUTING
    FORMAT=hostGroup

0 Karma

ralphw_SAIC
Path Finder

This looks to break things.

Simplifying my setup a bit, IDX-1 receives limited eventIDs for all hosts, IDX-2 receives all eventIDs for a subset of hosts.

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...