Security

How to direct certain sourcetypes into a non-default index

Alan_Bradley
Path Finder

When I've created a new index. how can I direct certain sourcetypes to be indexed in that new index, rather than into main?

Likewise, is it possible to have one or more sourcetypes indexed into multiple indexes simultaneously? The use case for this would be if you had two roles who were allowed to see only indexA and indexB, respectively, but there were some small amount of data that each needed to see in common.

Tags (2)
0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

It is easy to direct inputs to indexes by specifying an index clause where the input is defined. To direct by sourcetype, you must route using an index-time transform against MetaData:Sourcetype, and must furthermore make sure that your transform runs only after the sourcetype is set. In most cases, it's just as easy to set the index when you set the sourcetype anyway.

I would recommend you simply set up a third index for the overlap rather than trying to index data twice. There's not really a good way to do it, other than trickery involving forwarding the data to different ports on the same indexers or something along those lines.

View solution in original post

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

It is easy to direct inputs to indexes by specifying an index clause where the input is defined. To direct by sourcetype, you must route using an index-time transform against MetaData:Sourcetype, and must furthermore make sure that your transform runs only after the sourcetype is set. In most cases, it's just as easy to set the index when you set the sourcetype anyway.

I would recommend you simply set up a third index for the overlap rather than trying to index data twice. There's not really a good way to do it, other than trickery involving forwarding the data to different ports on the same indexers or something along those lines.

0 Karma
Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

REGISTER NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more ...

Security Highlights | November 2022 Newsletter

 November 2022 2022 Gartner Magic Quadrant for SIEM: Splunk Named a Leader for the 9th Year in a RowSplunk is ...

Platform Highlights | November 2022 Newsletter

 November 2022 Skill Up on Splunk with our New Builder Tech Talk SeriesCan you build it? Yes you can! *play ...