Getting Data In

_TCP_ROUTING with clustered indexers system logs

splunkreal
Motivator

Hello,

we have 2 Splunk platforms and we are using _TCP_ROUTING to forward logs.

System logs from 1st platform indexers are currently logged on themself.

 

We want to also receive system logs from  indexers of the 1st platform on our 2nd platform however there is no default tcpout group on 1st platform indexers.

 

So should we create default outputs.conf on 1st platform indexers to continue indexing local system logs?

 

Thanks for your help.

 

* If this helps, please upvote or accept solution if it solved *
Labels (5)
0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...