Getting Data In

TCP routing and change target index on secondary Splunk platform

splunkreal
Motivator

Hello,

We have two clustered Splunk platforms.

Several sources are sent to both platforms (directly to clustered indexers) as index app-idx1, then on 2nd platform we use different target index name using props.conf/transforms.conf to have application_idx2

For unknown reason few sources are failing to lastchanceindex.

 

props.conf

[source::/path/to/app_json.log]

TRANSFORMS-app-idx1 = set_idx1_index

 

transforms.conf

[set_idx1_index]

SOURCE_KEY = _MetaData:Index

REGEX = app-idx1

DEST_KEY = _MetaData:Index

FORMAT = application_idx2

 

Thanks for your help.

 

 

* If this helps, please upvote or accept solution if it solved *
0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

To troubleshoot your sources failing to lastchanceindex, I recommend checking if your REGEX pattern is too strict.






If this helps, Please Upvote.

If this helps, Upvote!!!!
Together we make the Splunk Community stronger 
0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...