I have a universal forwarder that sends 2 source types to heavy forwarder successfully. i need this heavy forwarder to route the received source types between 2 indexers.
My configurations on heavy forwarder is like below
props.conf
[cron]
TRANSFORMS-routing=cron-route
[syslog]
TRANSFORMS-routing=syslog-route
Transforms.conf
[cron-route]
DEST_KEY=_TCP_ROUTING
FORMAT=indexer-1
[syslog-route]
DEST_KEY=_TCP_ROUTING
FORMAT=indexer-2,indexer-1
outputs.conf
[tcpout:indexer-1]
server = 192.168.14.14:9997
[tcpout:indexer-2]
server = 192.168.14.15:9997
Thanks in advance
The document that discusses this can be found here:
At first glance, your configuration appears to be mostly right. I think you will also need to include the "REGEX" setting under each transforms.conf stanza.
[cron-route]
REGEX = (.)
DEST_KEY=_TCP_ROUTING
FORMAT=indexer-1
[syslog-route]
REGEX = (.)
DEST_KEY=_TCP_ROUTING
FORMAT=indexer-2,indexer-1
Try and and see if that works.
The document that discusses this can be found here:
At first glance, your configuration appears to be mostly right. I think you will also need to include the "REGEX" setting under each transforms.conf stanza.
[cron-route]
REGEX = (.)
DEST_KEY=_TCP_ROUTING
FORMAT=indexer-1
[syslog-route]
REGEX = (.)
DEST_KEY=_TCP_ROUTING
FORMAT=indexer-2,indexer-1
Try and and see if that works.
solved now,, thanks alot 🙂