Getting Data In

How do you route the same data to multiple indexes?

ankithreddy777
Contributor

I am onboarding a new data source. I need to send all of the data to index 1 and part of data to index 2. Is it possible to implement this using transforms? I know it's possible to send particular data to index 1 and remaining to null queue. Could you please help me regarding this?

0 Karma

DalJeanis
Legend
0 Karma

ankithreddy777
Contributor

Hi DalJeanis,

Are the any examples, how to implement it. unable to determine the data flow . I tried to clone sourcetype on indexers

0 Karma

somesoni2
Revered Legend

Look at the configuration in the question of following post, minus the setnull configs.

https://answers.splunk.com/answers/565396/can-i-still-send-data-to-nullqueue-while-using-met.html#co...

Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...