Getting Data In

TCP routing and change target index on secondary Splunk platform

splunkreal
Motivator

Hello,

We have two clustered Splunk platforms.

Several sources are sent to both platforms (directly to clustered indexers) as index app-idx1, then on 2nd platform we use different target index name using props.conf/transforms.conf to have application_idx2

For unknown reason few sources are failing to lastchanceindex.

 

props.conf

[source::/path/to/app_json.log]

TRANSFORMS-app-idx1 = set_idx1_index

 

transforms.conf

[set_idx1_index]

SOURCE_KEY = _MetaData:Index

REGEX = app-idx1

DEST_KEY = _MetaData:Index

FORMAT = application_idx2

 

Thanks for your help.

 

 

* If this helps, please upvote or accept solution if it solved *
0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

To troubleshoot your sources failing to lastchanceindex, I recommend checking if your REGEX pattern is too strict.






If this helps, Please Upvote.

If this helps, Upvote!!!!
Together we make the Splunk Community stronger 
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Maximizing the Value of Splunk ES 8.x

Splunk Enterprise Security (ES) continues to be a leader in the Gartner Magic Quadrant, reflecting its pivotal ...