Getting Data In

Solution : index renaming not working when using _TCP_ROUTING

splunkreal
Motivator

Hello, if you are using _TCP_ROUTING and index rename on target platform, logs may go to "last chance index" 

 

 

 

* If this helps, please upvote or accept solution if it solved *
0 Karma
1 Solution

splunkreal
Motivator

In this case review inputs.conf sourcetype and change it if you use default pretrained :

 

https://docs.splunk.com/Documentation/Splunk/9.3.0/Data/Listofpretrainedsourcetypes

 

"The source types marked with an asterisk ( * ) use the INDEXED_EXTRACTIONS attribute, which sets other attributes in props.conf to specific defaults and requires special handling to forward to another Splunk platform instance. See Forward fields extracted from structured data files."

* If this helps, please upvote or accept solution if it solved *

View solution in original post

0 Karma

splunkreal
Motivator

In this case review inputs.conf sourcetype and change it if you use default pretrained :

 

https://docs.splunk.com/Documentation/Splunk/9.3.0/Data/Listofpretrainedsourcetypes

 

"The source types marked with an asterisk ( * ) use the INDEXED_EXTRACTIONS attribute, which sets other attributes in props.conf to specific defaults and requires special handling to forward to another Splunk platform instance. See Forward fields extracted from structured data files."

* If this helps, please upvote or accept solution if it solved *
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...