Getting Data In

How do I clone all data received from one indexer to another indexer?

andrew207
Path Finder

Hello,

I have one indexer cluster that receives data over inputs.conf [splunktcp://9997].

I want to clone all data received by this indexer cluster on this port to another Splunk instance, which also listens on 9997. I understand this will double my license consumption.

Current: UF --> Indexer (stores all data)

Desire: UF --> Indexer (stores all data) --> Other Indexer (also stores all data)

How can I clone all data received on 9997 from one indexer to another?

Thanks

Labels (3)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @andrew207,

you can create a fork on your UF to send data to both Cluster and additional Indexes.

You have to add a group to outputs.conf, something like this:

[tcpout]
defaultGroup=indexer_cluster,Other_indexer

[tcpout:indexer_cluster]
server=xxx.xxx.xxx.xxx:9997

[tcpout:other_indexer]
server=yyy.yyy.yyy.yyy:9997

In other words, add both the addressing of the Cluster and the other Indexers.

Ciao.

Giuseppe

0 Karma

andrew207
Path Finder

Hello @gcusello 

I am performing the cloning from a source indexer, not from a uf. This means there is currently no outputs.conf configured, and your answer does not work.

Thanks

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @andrew207,

if you want to clone all the data of an Indexers sending them to another, you have only to configure your indexers to Forward data to another Indexes and locally store a copy of the files.

You can do this by GUI [Settings -- Forwarding and Receiving -- Forwarding]

It surely runs on a single Indexer, I never tried with a Cluster, but it should run.

Check if configuring for Forwarding only one peer of the Cluster you forward all the data or (as I suppose)  you need to configure all the peers.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...