Getting Data In

Internal logs forwarding to different group of indexers ?

rakesh_498115
Motivator

Hi,

I have a forwarder outputs configuration as below.

[tcpout]
defaultGroup = A_Indexers

[tcpout:A_Indexers]
server = 10.19.83.130:9997

[tcpout:B_Indexers]
server = 10.19.84.129:9997

[tcpout:C_Indexers]
server = 10.19.86.141:9997

Now the internal logs i mean splunkd are forwarding to C_indexers group , but in my configuration i have given them to forward to A_indexers as default group. but its not happening in the desired way . am i missing something...

I dont think we need to add TCP_ROUTING to the inputs configuration of internal logs (splunkd) since the default group in that server is already mentioned in outputs.conf configuration.

Please help.

Tags (1)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi rakesh_498115,

how did you setup the forwarding of the internal logs to those C_indexers?

Be aware that outputs.conf defaultGroup can be overridden by an inputs.conf _TCP_ROUTING setting, which in turn can be overridden by a props.conf or transforms.conf modifier.

cheers, MuS

0 Karma

theouhuios
Motivator

Any idea on this issue? I am seeing the same problem with _internal logs.

0 Karma

MuS
SplunkTrust
SplunkTrust

run this to see if you got some over laying configs here:

$SPLUNK_HOME/bin/splunk cmd btool outputs list

also look at this http://docs.splunk.com/Documentation/Splunk/6.0.2/Troubleshooting/Usebtooltotroubleshootconfiguratio...

0 Karma

rakesh_498115
Motivator

For internal logs in this particular server i have setup any forwarding setup Mus. as in my outputs.conf i defined default group as A_indexers , i expect them to go to A indexders. and in inputs.conf i have used _TCP_ROUTING parmater to forward the data to the desired indexers.

and there are no props.conf or transforms.conf settings involved for forwarding .. not sure why data is being sent to C_indexers instead of A_indexers.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...