Getting Data In

How do i disable forwarding for one sourcetype

pjcable
Engager

Hi,

We need to send some security events to an external party.  We also need this for our internal use.

On my test instance I've configured outputs.conf as

 

[tcpout]
defaultGroup = security
indexAndForward = 1

[tcpout:security]
server = localhost:9999

Which has got my events flowing to my fake external server and leaves them accessible in the internal side. However I only want to send 2 source types there. How do i filter out the rest of the events?

 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @pjcable,

as yu can read at https://docs.splunk.com/Documentation/Splunk/9.1.1/Forwarding/Routeandfilterdatad#Replicate_a_subset...

to add a stanza in outputs.conf isn't enough, follow the configuration at the above link.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...