Getting Data In
Highlighted

Will my outputs.conf edits work to send both compressed and uncompressed outputs from universal forwarder?

New Member

I have a Universal Forwarder (UF) that I'd like to send out both compressed and uncompressed data streams to a single indexer. Would this outputs.conf work:

[tcpout]
defaultGroup = index_cluster, index_cluster2

[tcpout:index_cluster]
autoLBFrequency=60
autoLB=true
useACK=true
compressed=true
server=indexer:9996

[tcpout:index_cluster2]
compressed=false
server=indexer:9997

Also, how would I specify which files/data streams should go out to targetGroup indexcluster and which ones should go out to indexcluster2?

Thanks,
Mike

0 Karma
Highlighted

Re: Will my outputs.conf edits work to send both compressed and uncompressed outputs from universal forwarder?

SplunkTrust
SplunkTrust

Yes, they will work this way.

This is saying by default, send to both.

If you want to specify a target specific to an input use TCPROUTING=name of tcpout on you inputs.conf stanza(s)

For example

[monitor::/var/log/logfile]
...
TCPROUTING=index_cluster2

View solution in original post