Getting Data In

How to send event from UF to multiple Heavy Forwarders and different indexers

randqm
Loves-to-Learn Everything

I have the following situation:

I have an universal forwarder that were sent logs to (HF1 and index=idx1)

Could you provide suggestions on how to configure this universal forwarder (UF) to send logs to both (HF1 and index=idx1) and (HF2 and index=idx2)?

Any insights or advice would be appreciated. Thank you.

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @randqm,

let me understand: do you want to send different logs to the two HFs or the same?

if the same, you have to configure the outputs.conf on the UF lke the following:

in outputs.conf:

[tcpout]
defaultGroup=HF1

[tcpout:HF1]
server=<ip_hf1>:9997

[tcpout:HF2]
server=<ip_hf2>:9997

in props.conf:

[default]
TRANSFORMS-routing=HF1

[syslog]
TRANSFORMS-routing=HF2

in transforms.conf

[HF1]
REGEX=.
DEST_KEY=_TCP_ROUTING
FORMAT=HF1

[HF2]
REGEX=.
DEST_KEY=_TCP_ROUTING
FORMAT=HF2

you can find more information at https://docs.splunk.com/Documentation/Splunk/9.0.4/Forwarding/Routeandfilterdatad

if you have to send different sets of data, you have to change the regexes in transforms.conf to filter data to send to HFs.

Ciao.

Giuseppe

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Remember that UFs don't do transforms unless you force_local_processing.

So it's better to set _TCP_ROUTING directly at input level.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

outputs.conf should be set as in @gcusello 's example but instead of props.conf and transforms.conf entries you just add

_TCP_ROUTING = HF1

or

_TCP_ROUTING = HF2

into input.conf stanzas depending on which output you want to point each data stream to.

0 Karma

randqm
Loves-to-Learn Everything

How can I configure to send to different indexers

0 Karma

randqm
Loves-to-Learn Everything

Thanks for the response
Do you can give me an example for the confs files?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...