Getting Data In

_TCP_ROUTING with clustered indexers system logs

splunkreal
Motivator

Hello,

we have 2 Splunk platforms and we are using _TCP_ROUTING to forward logs.

System logs from 1st platform indexers are currently logged on themself.

 

We want to also receive system logs from  indexers of the 1st platform on our 2nd platform however there is no default tcpout group on 1st platform indexers.

 

So should we create default outputs.conf on 1st platform indexers to continue indexing local system logs?

 

Thanks for your help.

 

* If this helps, please upvote or accept solution if it solved *
Labels (5)
0 Karma
Get Updates on the Splunk Community!

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Splunk Education Goes to Washington | Splunk GovSummit 2024

If you’re in the Washington, D.C. area, this is your opportunity to take your career and Splunk skills to the ...