Getting Data In

How to send event from UF to multiple Heavy Forwarders and different indexers

randqm
Loves-to-Learn Everything

I have the following situation:

I have an universal forwarder that were sent logs to (HF1 and index=idx1)

Could you provide suggestions on how to configure this universal forwarder (UF) to send logs to both (HF1 and index=idx1) and (HF2 and index=idx2)?

Any insights or advice would be appreciated. Thank you.

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @randqm,

let me understand: do you want to send different logs to the two HFs or the same?

if the same, you have to configure the outputs.conf on the UF lke the following:

in outputs.conf:

[tcpout]
defaultGroup=HF1

[tcpout:HF1]
server=<ip_hf1>:9997

[tcpout:HF2]
server=<ip_hf2>:9997

in props.conf:

[default]
TRANSFORMS-routing=HF1

[syslog]
TRANSFORMS-routing=HF2

in transforms.conf

[HF1]
REGEX=.
DEST_KEY=_TCP_ROUTING
FORMAT=HF1

[HF2]
REGEX=.
DEST_KEY=_TCP_ROUTING
FORMAT=HF2

you can find more information at https://docs.splunk.com/Documentation/Splunk/9.0.4/Forwarding/Routeandfilterdatad

if you have to send different sets of data, you have to change the regexes in transforms.conf to filter data to send to HFs.

Ciao.

Giuseppe

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Remember that UFs don't do transforms unless you force_local_processing.

So it's better to set _TCP_ROUTING directly at input level.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

outputs.conf should be set as in @gcusello 's example but instead of props.conf and transforms.conf entries you just add

_TCP_ROUTING = HF1

or

_TCP_ROUTING = HF2

into input.conf stanzas depending on which output you want to point each data stream to.

0 Karma

randqm
Loves-to-Learn Everything

How can I configure to send to different indexers

0 Karma

randqm
Loves-to-Learn Everything

Thanks for the response
Do you can give me an example for the confs files?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...