Getting Data In

Universal forwarder: how to forward different logs to different indexers?

arkadyz1
Builder

I have two different Splunk applications on two different search heads. Right now those search heads are also indexers, but this might change in the future.

Anyway: I defined two groups in etc/system/local/outputs.conf, and referred to one or another using _TCP_ROUTING in each monitor stanza in etc/system/local/inputs.conf. I also removed default stanza from outputs.conf, so that there are no default groups. Is this setup good enough for the purpose?

0 Karma

woodcock
Esteemed Legend

Another way you could do it is to stand up 2 different instances of Splunk, but I would only use this approach if at least one of your input types is compressed (e.g. *.gz, *zip, etc.) because the AQ is single-threaded and could use the help anyway.

acharlieh
Influencer

Offhand (quickly not looking at the docs) that sounds right. Are you seeing problems with it?

Edit: wait actually you may want to set the default routing to a dummy group if you don't want events to go anywhere by default.

arkadyz1
Builder

I haven't seen any problems yet, but wanted to double check if I'm not missing something. Thanks for this 'dummy group' remark - I'll take a look into it.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...