Getting Data In

Reroute host to different index

troy44112
Explorer

I am trying to figure out how to reroute a specific host to a different index.
For example, search results of host=1234test shows in index=best_life...
How would I change the index of host1234 from best_life to fall into a different index that exist already ie. (index=other_index)..

Labels (1)
0 Karma

ashvinpandey
Contributor

@troy44112 

Use props.conf and transforms.conf for this..

 

 #props.conf
 [source]
 TRANSFORMS-routing_for_norris_index = route_to_norris_index

 #transforms.conf
 [route_to_norris_index]
 DEST_KEY = _MetaData:Index
 REGEX = chuck
 FORMAT = norris

 

This will route all events containing chuck into the norris index.


please find the below link for more detailed info:
https://blog.avotrix.com/implement-split-indexing-in-splunk/ 
Also, If this reply helps you, an upvote would be appreciated.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Check the inputs.conf files on that host.  Change all instances of "index=best_life" to "index=other_index" and restart Splunk on that host.

Data that is already in index=best_life cannot be moved, but you can use the collect command to copy events to another index.  This will affect your license usage.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...