We have indexers and Universal Forwarders and no Heavy Forwarders in use, i know UF cannot send parsed data to any external system it can only send uncooked data and all of them , but can the indexers send the parsed logs(only specific e.g. from windows index) to external system, maybe through REST API or syslog or any other mechanism?
the sequence would be like this : UF>>Indexers>>External System.
Hi @warsaw
yes you can route your data on third system native based on syslog.
check this page under "Replicate a subset of data to a third-party system"
https://docs.splunk.com/Documentation/Splunk/8.1.3/Forwarding/Routeandfilterdatad
@aasabatini yes i'd checked this already, this shows how to route cooked logs from HF to indexer and raw to external system, not cooked data from indexer to external system.
Hi @warsaw
yes you can route your data from your indexer specify the all condition on the outputs.conf
for example if you want index a syslog source and forward from indexer you need to specify on your stanza this.
[indexAndForward]
index=true
selectiveIndexing=true
Also on your forwarder if you want manage your source you need to specify the inputs stanza.
[input_stanza]
_INDEX_AND_FORWARD_ROUTING=<any_string>
I hope this link can help
https://docs.splunk.com/Documentation/Splunk/latest/Admin/Outputsconf#IndexAndForward_Processor-----
I see this is available for only heavy forwarders.
indexAndForward = <boolean> * Set to "true" to index all data locally, in addition to forwarding it. * This is known as an "index-and-forward" configuration. * This setting is only available for heavy forwarders. * This setting is only available at the top level [tcpout] stanza. It cannot be overridden in a target group. * Default: false
Hi @warsaw
the
indexAndForward
stanza works for all splunk roles.
check this answer is more similar on your case.