Getting Data In

How to send event from UF to multiple Heavy Forwarders and different indexers

randqm
Loves-to-Learn Everything

I have the following situation:

I have an universal forwarder that were sent logs to (HF1 and index=idx1)

Could you provide suggestions on how to configure this universal forwarder (UF) to send logs to both (HF1 and index=idx1) and (HF2 and index=idx2)?

Any insights or advice would be appreciated. Thank you.

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @randqm,

let me understand: do you want to send different logs to the two HFs or the same?

if the same, you have to configure the outputs.conf on the UF lke the following:

in outputs.conf:

[tcpout]
defaultGroup=HF1

[tcpout:HF1]
server=<ip_hf1>:9997

[tcpout:HF2]
server=<ip_hf2>:9997

in props.conf:

[default]
TRANSFORMS-routing=HF1

[syslog]
TRANSFORMS-routing=HF2

in transforms.conf

[HF1]
REGEX=.
DEST_KEY=_TCP_ROUTING
FORMAT=HF1

[HF2]
REGEX=.
DEST_KEY=_TCP_ROUTING
FORMAT=HF2

you can find more information at https://docs.splunk.com/Documentation/Splunk/9.0.4/Forwarding/Routeandfilterdatad

if you have to send different sets of data, you have to change the regexes in transforms.conf to filter data to send to HFs.

Ciao.

Giuseppe

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Remember that UFs don't do transforms unless you force_local_processing.

So it's better to set _TCP_ROUTING directly at input level.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

outputs.conf should be set as in @gcusello 's example but instead of props.conf and transforms.conf entries you just add

_TCP_ROUTING = HF1

or

_TCP_ROUTING = HF2

into input.conf stanzas depending on which output you want to point each data stream to.

0 Karma

randqm
Loves-to-Learn Everything

How can I configure to send to different indexers

0 Karma

randqm
Loves-to-Learn Everything

Thanks for the response
Do you can give me an example for the confs files?

0 Karma
Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability As businesses scale ...