Getting Data In

How to effectively route non-internal logs to external Indexers ?

dm1
Contributor

In my current setup, I want to forward only internal logs to Indexers in myOrg, whereas, some non-internal logs to Indexers of an external Org.

Below is my current outputs.conf, however, its not working as intended. I am seeing forwarder attempting to forward non-internal logs to myOrg's indexers as well.

 

 

[tcpout]
defaultGroup = Internal_indexers

#disable default filters
forwardedindex.0.whitelist =
forwardedindex.1.blacklist =
forwardedindex.2.whitelist =
forwardedindex.3.whitelist =

#Enable these
forwardedindex.4.whitelist = (_audit|_introspection|_internal|_telemetry)

[tcpout:Internal_indexers]
server = index01:9997

[tcpout:OrgA_indexer]
server = y.y.y.y:9997

 

Update:

Below is inputs.conf for non-internal log

[monitor://some_source.log]
index = abc
sourcetype = syslog
_TCP_ROUTING = OrgA_indexer

 

Labels (2)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @dm1 

Can you try this out as you are setting at defaultGroup level you might need to block other non-internals.

[tcpout]
defaultGroup = Internal_indexers
#disable default filters
forwardedindex.0.whitelist = (_audit|_introspection|_internal|_telemetry)
forwardedindex.1.blacklist = .*

_TCP_ROUTING to other indexer should work fine without any issues , hope you have done a restart of UF post this change and are you sure this OrgA indexer is in active forwarder list? Try ./splunk list forward-server

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...