Getting Data In

How to forward indexed data to another splunk receiver?

ford1863
New Member

Now I configured server A and B with installing splunk, and index some local logs on server A. I want to forward these logs to server B, and wrote some configure files in /opt/splunk/etc/system/local.

props.conf:

[<sourcetype>]
TRANSFORMS-routing=send_to_windows

transforms.conf:
[send_to_windows]
REGEX=.
DEST_KEY=_TCP_ROUTING
FORMAT=windowsgroup

outputs.conf:
[tcpout:windowsgroup]
disable=fasle
server=x.x.x.x:x

The server A is configured as Splunk forwarder mode.The piont is there's no logs receiving on server B.

Tags (1)
0 Karma

woodcock
Esteemed Legend

This looks good; did you configure the receiving side with something like this?

[splunktcp://9997]
connection_host = dns
index = myindex
sourcetype = mysourcetype
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...