Getting Data In

How do I forward specific Splunk 5.x indexes to Splunk 6.x?

JSkier
Communicator

I'm trying to forward specific indexes to a test splunk box with the latest version. So, I set forwarding defaults to keep indexing on v5. Configured a TCP port and set v5 to forward to v6, and I get everything (as expected) as noted by the plethora of index missing errors on v6. How do I only send the indexes I specifically want to v6?

I found a few very old answers (v1/2) on splunk core and this older documentation that seems to somewhat address what I'm trying to do, but I still get everything sent to v6 after whitelisting what I want: http://docs.splunk.com/Documentation/Splunk/4.3.3/Deploy/Routeandfilterdatad#Filter_data_by_target_i...

To be clear, I don't want to copy files or buckets over; I want the old version to keep indexing while adding the new data to the new version for testing.

I am very comfortable in Linux, but a bit spotty with splunk itself. Any help is much appreciated!

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

JSkier
Communicator

Tried restarting the forwarder and splunk service, still sending all logs.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Restarted the forwarding Splunk?

0 Karma

JSkier
Communicator

Still getting other events forwarded. I white listed one index and blacklisted a wild card (*).

0 Karma

JSkier
Communicator

Looks like the correct file to use is $SPLUNK_HOME/etc/system/local/. Haven't recieved anything yet, I'll let it sit. I did have to add the white list line again after adding the forward data back on.

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...