Getting Data In

Universal forwarder: how to forward different logs to different indexers?

arkadyz1
Builder

I have two different Splunk applications on two different search heads. Right now those search heads are also indexers, but this might change in the future.

Anyway: I defined two groups in etc/system/local/outputs.conf, and referred to one or another using _TCP_ROUTING in each monitor stanza in etc/system/local/inputs.conf. I also removed default stanza from outputs.conf, so that there are no default groups. Is this setup good enough for the purpose?

0 Karma

woodcock
Esteemed Legend

Another way you could do it is to stand up 2 different instances of Splunk, but I would only use this approach if at least one of your input types is compressed (e.g. *.gz, *zip, etc.) because the AQ is single-threaded and could use the help anyway.

acharlieh
Influencer

Offhand (quickly not looking at the docs) that sounds right. Are you seeing problems with it?

Edit: wait actually you may want to set the default routing to a dummy group if you don't want events to go anywhere by default.

arkadyz1
Builder

I haven't seen any problems yet, but wanted to double check if I'm not missing something. Thanks for this 'dummy group' remark - I'll take a look into it.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...