Getting Data In

Replicate a subset of data to a third-party system for specific index

evinasco
Communicator

Hi team

i need to foward a copy data from specific index to third-party system, someone knows how i can do that

regards

Tags (1)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi evinasco,

Have a look at the docs here https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad#Replicate_a_subse...

Please note, that this setting is only configurable based on host, source or sourcetype but NOT on index.

Hope this helps ...

cheers, MuS

0 Karma

evinasco
Communicator

Hi @MuS, Do you know if this configuration shall do in the transforms.conf?

[routeAll]
REGEX=(.)
DEST_KEY=_TCP_ROUTING
FORMAT=Everything

[routeSubset]
REGEX=(sourcetype1|sourcetype2|sourcetype3)
DEST_KEY=_TCP_ROUTING
FORMAT=Subsidiary,Everything

regadrs

0 Karma

MuS
SplunkTrust
SplunkTrust

Actually something like this would make more sense:

props.conf

[sourcetype1]
TRANSFORMS-001-Send-Subsidiary-sourcetype1 = Send-Subsidiary-sourcetype

[sourcetype2]
TRANSFORMS-002-Send-Subsidiary-sourcetype2 = Send-Subsidiary-sourcetype

[sourcetype1]
TRANSFORMS-003-Send-Subsidiary-sourcetype3 = Send-Subsidiary-sourcetype

transforms.conf

[Send-Subsidiary-sourcetype]
DEST_KEY = _TCP_ROUTING
FORMAT = Subsidiary, Everything

The reason for that is if you send everything by default to one destination, there is no need to configure a transforms stanza for this and add additional parsing load for these events 😉

Hope that makes sense ...

cheers, MuS

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...