Getting Data In

How do i disable forwarding for one sourcetype

pjcable
Engager

Hi,

We need to send some security events to an external party.  We also need this for our internal use.

On my test instance I've configured outputs.conf as

 

[tcpout]
defaultGroup = security
indexAndForward = 1

[tcpout:security]
server = localhost:9999

Which has got my events flowing to my fake external server and leaves them accessible in the internal side. However I only want to send 2 source types there. How do i filter out the rest of the events?

 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @pjcable,

as yu can read at https://docs.splunk.com/Documentation/Splunk/9.1.1/Forwarding/Routeandfilterdatad#Replicate_a_subset...

to add a stanza in outputs.conf isn't enough, follow the configuration at the above link.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...