Getting Data In

Can you send different logs to different Indexers from the same forwarder?

New Member

I would like to be able to send Log A to Indexer A and Log B to Indexer B from one forwarder.

0 Karma


Hi zbumpers,

From my experience, it is possible to achieve this. You just need to set the proper indexer destination in outputs.conf of the forwarder. Create tcpout groups and then specify the groups to the proper monitoring stanza in inputs.conf. For example, something like this:

Your indexers: and

In your forwarder:




# Add attributes to your monitor like sourcetype, index, etc
# In the end, specify to which indexer this log should be sent using _TCP_ROUTING = <group name>

# Do the same for log B

Restart the forwarder and see the result. Hope this helps.


Get Updates on the Splunk Community!

New Cloud Intrusion Detection System Add-on for Splunk

In July 2022 Splunk released the Cloud IDS add-on which expanded Splunk capabilities in security and data ...

Happy CX Day to our Community Superheroes!

Happy 10th Birthday CX Day!What is CX Day? It’s a global celebration recognizing innovation and success in the ...

Check out This Month’s Brand new Splunk Lantern Articles

Splunk Lantern is a customer success center providing advice from Splunk experts on valuable data insights, ...