Knowledge Management

How to send specific logs to another heavy Forwarder?

shimab11
Engager

Hi all,

I want to send specific logs from one Heavy Forwarder to another heavy Forwarder. I don't want to send a full logs i just need to send One of sourcetypes to another Heavy Forwarder.Version of splunk is 9.0.4

How can I do that?

Thx.

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @shimab11,

you have to follow the instructions at https://docs.splunk.com/Documentation/Splunk/9.1.0/Forwarding/Routeandfilterdatad#Filter_and_route_e...

In few words, on the first HF you have to modify:

  • outputs.conf: adding both the destination and giving to each of them a logical name to use in transforms.conf,
  • props.conf: adding a transformation to the sourcetype to send,
  • transforms.conf: adding the tranformation that define where to send data.

In my experience, sometimes it doesn't run so you have to add "_TCP_ROUTING = seconf_HF_group_name" to your inputs.conf

Ciao.

Giuseppe

isoutamo
SplunkTrust
SplunkTrust

Hi

You need to setup two output groups on HF. Then use props and transforms conf to select target group based on event content or source. There are several examples on community and docs are described how to do it. 

r. Ismo

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...