Getting Data In

Multiple index locations for forwarder

aaronkorn
Splunk Employee
Splunk Employee

Is there a way on the universal forwarder to send different data types to different indexers? For example, we want to send logA to indexerA and logB to indexerB from the same system where the universal forwarder is installed.

0 Karma

Ayn
Legend

Yes. Just specify index=theindexyouwanttouse in the monitor in inputs.conf.

0 Karma

Ayn
Legend

My apologies, I missed that 'r' in 'indexers' 🙂

In that case my answer would be no. You could do that with a Splunk instance that performs parsing, but Universal Forwarders don't do that.

0 Karma

aaronkorn
Splunk Employee
Splunk Employee

But the different indexes reside on different servers.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...