Getting Data In

Forwarding and receiving pre setup

gdawoud
Engager

I have a simple Forwarding and receiving setup

2 servers forwarding into a 3rd.

Once everything setup, the receiver started to get data from that point on. My Q is how do i push all the data that is indexed on the forwarder to the receiver before the setup of the "Forwarding and receiving"

1 Solution

jbsplunk
Splunk Employee
Splunk Employee

I am not sure I understand your question. However, if you are asking if there is some method of forwarding data to an indexer before it has been set up as a receiver, the answer is No, you've got to set up the indexer as a receiever before any forwarder will be able to send to it.

You could alternatively set up some mechanisms to transfer files periodically to the indexer and set up monitor stanzas for those files, then turn them off after the forwarder has been enabled.

View solution in original post

0 Karma

jbsplunk
Splunk Employee
Splunk Employee

I am not sure I understand your question. However, if you are asking if there is some method of forwarding data to an indexer before it has been set up as a receiver, the answer is No, you've got to set up the indexer as a receiever before any forwarder will be able to send to it.

You could alternatively set up some mechanisms to transfer files periodically to the indexer and set up monitor stanzas for those files, then turn them off after the forwarder has been enabled.

0 Karma

gdawoud
Engager

You are correct, I got it fixed but setting the install (1&2) to forward to 3 before adding files to server 1&2

G

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...