Getting Data In

How do you route the same data to multiple indexes?

ankithreddy777
Contributor

I am onboarding a new data source. I need to send all of the data to index 1 and part of data to index 2. Is it possible to implement this using transforms? I know it's possible to send particular data to index 1 and remaining to null queue. Could you please help me regarding this?

0 Karma

DalJeanis
Legend
0 Karma

ankithreddy777
Contributor

Hi DalJeanis,

Are the any examples, how to implement it. unable to determine the data flow . I tried to clone sourcetype on indexers

0 Karma

somesoni2
Revered Legend

Look at the configuration in the question of following post, minus the setnull configs.

https://answers.splunk.com/answers/565396/can-i-still-send-data-to-nullqueue-while-using-met.html#co...

Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...