Getting Data In

How to effectively route non-internal logs to external Indexers ?

dm1
Contributor

In my current setup, I want to forward only internal logs to Indexers in myOrg, whereas, some non-internal logs to Indexers of an external Org.

Below is my current outputs.conf, however, its not working as intended. I am seeing forwarder attempting to forward non-internal logs to myOrg's indexers as well.

 

 

[tcpout]
defaultGroup = Internal_indexers

#disable default filters
forwardedindex.0.whitelist =
forwardedindex.1.blacklist =
forwardedindex.2.whitelist =
forwardedindex.3.whitelist =

#Enable these
forwardedindex.4.whitelist = (_audit|_introspection|_internal|_telemetry)

[tcpout:Internal_indexers]
server = index01:9997

[tcpout:OrgA_indexer]
server = y.y.y.y:9997

 

Update:

Below is inputs.conf for non-internal log

[monitor://some_source.log]
index = abc
sourcetype = syslog
_TCP_ROUTING = OrgA_indexer

 

Labels (2)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @dm1 

Can you try this out as you are setting at defaultGroup level you might need to block other non-internals.

[tcpout]
defaultGroup = Internal_indexers
#disable default filters
forwardedindex.0.whitelist = (_audit|_introspection|_internal|_telemetry)
forwardedindex.1.blacklist = .*

_TCP_ROUTING to other indexer should work fine without any issues , hope you have done a restart of UF post this change and are you sure this OrgA indexer is in active forwarder list? Try ./splunk list forward-server

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...