Splunk Enterprise Security

notable index forwarding into indexer cluster.

AShwin1119
Explorer

we have our environment in google cloud platform where we have SH cluster with 3 SH.
and earlier the issue was notable index data was getting stored locally in each search head to fix this we have created the notable index at indexer cluster and then forwarded the SH data toward the Indexer cluster using "indexer discovery" method, now the problem is the configuration (props.conf & transform.conf) which were responsible to redirect the data to notable index locally (each SH) are not taking effect to forward the data into notable index created in indexer cluster. however internal index data are forwarding now in the indexer cluster.

0 Karma

meetmshah
SplunkTrust
SplunkTrust

Hello @AShwin1119 Would you be able to confirm why we need to have props / transforms configuration? As far as I understand, we can just have default _TCP_ROUTING configured to send all SH events to Indexers through outputs configurations - isn't it?

Ref Doc - https://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Forwardsearchheaddata

0 Karma

meetmshah
SplunkTrust
SplunkTrust

@AShwin1119 Did you went through the response and have any further questions?

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...