Getting Data In

How to send event from UF to multiple Heavy Forwarders and different indexers

randqm
Loves-to-Learn Everything

I have the following situation:

I have an universal forwarder that were sent logs to (HF1 and index=idx1)

Could you provide suggestions on how to configure this universal forwarder (UF) to send logs to both (HF1 and index=idx1) and (HF2 and index=idx2)?

Any insights or advice would be appreciated. Thank you.

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @randqm,

let me understand: do you want to send different logs to the two HFs or the same?

if the same, you have to configure the outputs.conf on the UF lke the following:

in outputs.conf:

[tcpout]
defaultGroup=HF1

[tcpout:HF1]
server=<ip_hf1>:9997

[tcpout:HF2]
server=<ip_hf2>:9997

in props.conf:

[default]
TRANSFORMS-routing=HF1

[syslog]
TRANSFORMS-routing=HF2

in transforms.conf

[HF1]
REGEX=.
DEST_KEY=_TCP_ROUTING
FORMAT=HF1

[HF2]
REGEX=.
DEST_KEY=_TCP_ROUTING
FORMAT=HF2

you can find more information at https://docs.splunk.com/Documentation/Splunk/9.0.4/Forwarding/Routeandfilterdatad

if you have to send different sets of data, you have to change the regexes in transforms.conf to filter data to send to HFs.

Ciao.

Giuseppe

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Remember that UFs don't do transforms unless you force_local_processing.

So it's better to set _TCP_ROUTING directly at input level.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

outputs.conf should be set as in @gcusello 's example but instead of props.conf and transforms.conf entries you just add

_TCP_ROUTING = HF1

or

_TCP_ROUTING = HF2

into input.conf stanzas depending on which output you want to point each data stream to.

0 Karma

randqm
Loves-to-Learn Everything

How can I configure to send to different indexers

0 Karma

randqm
Loves-to-Learn Everything

Thanks for the response
Do you can give me an example for the confs files?

0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...