Getting Data In

How to mirror a summary index without cluster or distributed search?

kurdbahr
Path Finder

I have a standalone server (6.1.x) running some scheduled searches to consolidate data from multiple large sources into one summary index.
Now I would like to make this summary data simultaneously available on an other standalone server (6.2.x) without setting up a cluster or distributed search.

My current idea is to set up a script action for the scheduled searches that copies the stash files to a network share where it is then read by the other indexer.
Any better ideas?
Is it possible to forward the summary data to the other server?
Maybe by configuring TCP_ROUTING for the "stash" sourcetype in inputs.conf?

1 Solution

kurdbahr
Path Finder

After some hours of digging through the docs this seems to be a working configuration:

etc/system/local/props.conf:

[stash_new]
TRANSFORMS-my_routing_class=my_summary_routing

etc/system/local/transforms.conf:

[my_summary_routing]
SOURCE_KEY=_MetaData:Index
DEST_KEY=_TCP_ROUTING
REGEX=my_summary_index
FORMAT=my_remote_group

etc/system/local/outputs.conf:

[tcpout]
defaultGroup=my_non_existing_group
indexAndForward=true

[tcpout:my_remote_group]
server=192.168.178.31:9996

View solution in original post

kurdbahr
Path Finder

After some hours of digging through the docs this seems to be a working configuration:

etc/system/local/props.conf:

[stash_new]
TRANSFORMS-my_routing_class=my_summary_routing

etc/system/local/transforms.conf:

[my_summary_routing]
SOURCE_KEY=_MetaData:Index
DEST_KEY=_TCP_ROUTING
REGEX=my_summary_index
FORMAT=my_remote_group

etc/system/local/outputs.conf:

[tcpout]
defaultGroup=my_non_existing_group
indexAndForward=true

[tcpout:my_remote_group]
server=192.168.178.31:9996
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...