Getting Data In

How do you route the same data to multiple indexes?

ankithreddy777
Contributor

I am onboarding a new data source. I need to send all of the data to index 1 and part of data to index 2. Is it possible to implement this using transforms? I know it's possible to send particular data to index 1 and remaining to null queue. Could you please help me regarding this?

0 Karma

DalJeanis
Legend
0 Karma

ankithreddy777
Contributor

Hi DalJeanis,

Are the any examples, how to implement it. unable to determine the data flow . I tried to clone sourcetype on indexers

0 Karma

somesoni2
Revered Legend

Look at the configuration in the question of following post, minus the setnull configs.

https://answers.splunk.com/answers/565396/can-i-still-send-data-to-nullqueue-while-using-met.html#co...

Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...