Getting Data In

How to forward data from one Splunk indexer to another indexer?


I have created an outputs.conf on my Indexer. With the following stanza.

defaultGroup = indexerB


server =

This is not having the intended results. I'm expecting all data being sent that particular Splunk Indexer to be forwarded to indexerB on dst port tcp/9997.
This is the only output we see;
server01234 8089 @ _s2s_capabilities ack=0;compression=0 _raw --splunk-cooked-mode-v3-- server01234

0 Karma

Splunk Employee
Splunk Employee

Your input port on the receiver needs to be defined as "splunktcp" not "tcp".

0 Karma
Get Updates on the Splunk Community!

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...

Reminder! Splunk Love Promo: $25 Visa Gift Card for Your Honest SOAR Review With ...

We recently launched our first Splunk Love Special, and it's gone phenomenally well, so we're doing it again, ...