Getting Data In

Intermediate forwarder not forwarding _internal data

mohankesireddy
Path Finder

I am using Universal Forwarder as Intermediate forwarder, it is forwarding the monitored data without any issues but it is not forwarding any data _internal index or Splunk logs.

Intermediate Forwarder Configuration:
Outputs.conf
[tcpout:index]
server=sra-index-01:9997,sra-index-02:9997,sra-index-03:9997,sra-index-04:9997,sra-index-05:9997

inputs.conf
[splunktcp://9997]
disabled=0

1 Solution

dmaislin_splunk
Splunk Employee
Splunk Employee

[tcpout]
forwardedindex.filter.disable = true

View solution in original post

dmaislin_splunk
Splunk Employee
Splunk Employee

[tcpout]
forwardedindex.filter.disable = true

mohankesireddy
Path Finder

Thanks dmaislin, it worked.

0 Karma

archspangler
Path Finder

Worked for me as well.

0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...