Splunk Enterprise Security

notable index forwarding into indexer cluster.

AShwin1119
Explorer

we have our environment in google cloud platform where we have SH cluster with 3 SH.
and earlier the issue was notable index data was getting stored locally in each search head to fix this we have created the notable index at indexer cluster and then forwarded the SH data toward the Indexer cluster using "indexer discovery" method, now the problem is the configuration (props.conf & transform.conf) which were responsible to redirect the data to notable index locally (each SH) are not taking effect to forward the data into notable index created in indexer cluster. however internal index data are forwarding now in the indexer cluster.

0 Karma

meetmshah
SplunkTrust
SplunkTrust

Hello @AShwin1119 Would you be able to confirm why we need to have props / transforms configuration? As far as I understand, we can just have default _TCP_ROUTING configured to send all SH events to Indexers through outputs configurations - isn't it?

Ref Doc - https://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Forwardsearchheaddata

0 Karma

meetmshah
SplunkTrust
SplunkTrust

@AShwin1119 Did you went through the response and have any further questions?

Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...