Deployment Architecture

routing assistance config - HEC to multiple envs

Esky73
Builder

i am receiving data via HEC to a SH which then sends to an index tier.

I've like to also send this data to a secondary indexing tier which is a separate env - need some clarification with the config is the section 'Forward data for a single index only' relevant here - will it still index locally ?

http://docs.splunk.com/Documentation/Splunk/7.1.0/Forwarding/Routeandfilterdatad#Perform_selective_i...

[tcpout]
#Disable the current filters from the defaults outputs.conf
forwardedindex.0.whitelist = 
forwardedindex.1.blacklist =
forwardedindex.2.whitelist =

#Forward data for the "myindex" index
forwardedindex.0.whitelist = myindex
Tags (1)
0 Karma

shelde_msearles
New Member

Did this end up working as you expected?

0 Karma

xpac
SplunkTrust
SplunkTrust

So - you want to send the HEC data to two different destinations?
You sent ALL data from that instance to a certain index tier, by default, and for some data, want to also send that data to a second destination?

0 Karma

Esky73
Builder

hey xpac - correct.

It's not an ideal scenario - just a workaround to send the HEC data to another test env.

0 Karma
Get Updates on the Splunk Community!

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...