Security

Send Notable events to stand alone indexer

islam
Explorer

Hi,

how can we send ES notable events from cluster setup to a stand alone indexer.

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Tell us more, please.  What problem are you trying to solve?  What is the "cluster setup" - indexer or SH cluster?

---
If this reply helps you, Karma would be appreciated.
0 Karma

islam
Explorer

we have main setup with indexer cluster and a search head with ES over it and a small setup consists of an indexer and a search head.

we need to forward all notable events from the main setup to the small setup.

how can we do that?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I sounds like you're referring to Index and Forward.  See https://docs.splunk.com/Documentation/Splunk/8.2.2/Forwarding/Routeandfilterdatad#Perform_selective_...

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...