Getting Data In

tcp_routing route every thing?

crazyeva
Contributor

i am test '_tcp_routing' in my virtual machines, before doing that on online system.
simply i add:
[monitor://afile]
_tcp_routing = forward-group
...
to inputs.conf

and
[tcpout:forward-group]
server = anothersplunkinstance:9997
to outputs.conf

i did these configuration before first-time-run-splunk

after i started splunk --accept-license
i found nothing in splunk, idx main is clean(supposed to receive some other data), even _internal, _*** were all empty.

did 'tcp_routing' forward all my data to anothersplunkinstance:9997,which i set up as an Universal Forwarder?

Tags (1)
0 Karma

jenipherc
Splunk Employee
Splunk Employee

Wow. This is such an old article that deserved a belated response.
I wonder where you put your inputs.conf and outputs.conf because that matters.

Use btool to get the final configuration that Splunk accepts, and also review this documentation for more info.
https://docs.splunk.com/Documentation/Splunk/6.5.0/Admin/Wheretofindtheconfigurationfiles

0 Karma
Get Updates on the Splunk Community!

Insights from .conf 2025, Smart Edge Processor Scaling, and a New Splunk Lantern ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Machine Learning - Assisted Adaptive Thresholding

Let’s talk thresholding. Have you set up static thresholds? Tired of static thresholds triggering false ...

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...