Getting Data In

How to forward indexed data to another splunk receiver?

ford1863
New Member

Now I configured server A and B with installing splunk, and index some local logs on server A. I want to forward these logs to server B, and wrote some configure files in /opt/splunk/etc/system/local.

props.conf:

[<sourcetype>]
TRANSFORMS-routing=send_to_windows

transforms.conf:
[send_to_windows]
REGEX=.
DEST_KEY=_TCP_ROUTING
FORMAT=windowsgroup

outputs.conf:
[tcpout:windowsgroup]
disable=fasle
server=x.x.x.x:x

The server A is configured as Splunk forwarder mode.The piont is there's no logs receiving on server B.

Tags (1)
0 Karma

woodcock
Esteemed Legend

This looks good; did you configure the receiving side with something like this?

[splunktcp://9997]
connection_host = dns
index = myindex
sourcetype = mysourcetype
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...