Getting Data In

How to send a specific index from one indexer to another without a heavy forwarder

troyfred
Explorer

So we have a client system that has their own Splunk indexer.
For certain reasons they do not want their splunk universal forwarders sending logs to two separate indexers, but want to continue to have all their logs sent to their indexer, and then forward select indexes from their indexer to ours.

Most of the indexandforward items seem to require a heavy forwarder to work.
We are trying not to interfere with their current setup as much as possible and adding the heavy forwarder seems like it would be exactly that. Any thoughts would be greatly appreciated.

skrajkumar_splu
Splunk Employee
Splunk Employee

Hi Troyfred

One suggestion is instead of forwarding the logs from one indexer to another. You can configure the UF to send only specific monitors to the second indexer( Or even both indexers) via _TCP_ROUTING. Define two different routing groups for both scenarios in outputs.conf and declare the group in inputs.conf.

Refer inputs.conf.specs for more info

https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf

0 Karma

dauren_akilbeko
Communicator

What you could do is enable Heavy Forwarder on the customer indexer and then use selective indexing/forwarding to forward and store needed indexes. Don't forget to backup config.

0 Karma

anmolpatel
Builder

One suggestion: setup distributed searches and add the indexers as search peers is an option. You can restrict index access by roles. Added benefit, license is not consumed by both the teams for the same data.
https://docs.splunk.com/Documentation/Splunk/8.0.2/DistSearch/Configuredistributedsearch

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...