Getting Data In

tcp_routing route every thing?

crazyeva
Contributor

i am test '_tcp_routing' in my virtual machines, before doing that on online system.
simply i add:
[monitor://afile]
_tcp_routing = forward-group
...
to inputs.conf

and
[tcpout:forward-group]
server = anothersplunkinstance:9997
to outputs.conf

i did these configuration before first-time-run-splunk

after i started splunk --accept-license
i found nothing in splunk, idx main is clean(supposed to receive some other data), even _internal, _*** were all empty.

did 'tcp_routing' forward all my data to anothersplunkinstance:9997,which i set up as an Universal Forwarder?

Tags (1)
0 Karma

jenipherc
Splunk Employee
Splunk Employee

Wow. This is such an old article that deserved a belated response.
I wonder where you put your inputs.conf and outputs.conf because that matters.

Use btool to get the final configuration that Splunk accepts, and also review this documentation for more info.
https://docs.splunk.com/Documentation/Splunk/6.5.0/Admin/Wheretofindtheconfigurationfiles

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...