Now I configured server A and B with installing splunk, and index some local logs on server A. I want to forward these logs to server B, and wrote some configure files in /opt/splunk/etc/system/local.
props.conf:
[<sourcetype>]
TRANSFORMS-routing=send_to_windows
transforms.conf:
[send_to_windows]
REGEX=.
DEST_KEY=_TCP_ROUTING
FORMAT=windowsgroup
outputs.conf:
[tcpout:windowsgroup]
disable=fasle
server=x.x.x.x:x
The server A is configured as Splunk forwarder mode.The piont is there's no logs receiving on server B.
This looks good; did you configure the receiving side with something like this?
[splunktcp://9997]
connection_host = dns
index = myindex
sourcetype = mysourcetype