Getting Data In

How to forward the event of a specific index on the heavy forwarder to the specified index of another indexer?

xsstest
Communicator

I have a separate Splunk Enterprise instance, The 9997 port has been enabled to receive events from each host and set up their own index for them。For example: apache_access, secure ect .....

now , I want to convert it into a heavy forwarder and forwards these events to an indexer cluster.

So the question is coming,

How do I forward the event of a specific index on the heavy forwarder, (for example: apache_access) to the specified index of the indexer cluster (for example: web_apache_access)

Example:

apache_access (from heavy-forwarder) ————————>Forward TO ————>web_apache_access(indexer clustering)

0 Karma
1 Solution

xsstest
Communicator

You only need to enable heavy-forwarder
As long as the heavy-forwarder and indexer clusters have the same index name.

For information on how to enable heavy forwarder, read the documentation: http://docs.splunk.com/Documentation/Splunk/6.6.1/Forwarding/Deployaheavyforwarder

View solution in original post

0 Karma

xsstest
Communicator

You only need to enable heavy-forwarder
As long as the heavy-forwarder and indexer clusters have the same index name.

For information on how to enable heavy forwarder, read the documentation: http://docs.splunk.com/Documentation/Splunk/6.6.1/Forwarding/Deployaheavyforwarder

0 Karma

xsstest
Communicator

Why no one answered the question?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...