Splunk Enterprise

HF send data to specific index

zafiro
Explorer

How can i setup the heavy forwarder to output data to a user created index in the indexer splunk instance?

My HF does not store data locally, I want it be sent only to the remote indexer.

I have tried setting up inputs.conf and outputs.conf but I'm not sure where is the right place to do this in the HF folder structure and if this is the correct approach. 

 

thank u!

 

Labels (1)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @zafiro 

Is the data originating on the HF or is being sent to the HF from another source?

If its originating on the HF then you should be able to set index=<indexName> in the relevant stanzas of your inputs.conf on the HF. You'll need to restart for this to take affect.

If the data originates somewhere else then you'll need to use props/transforms to re-write the index name based, is it all data arriving on that HF that needs the index changing? What is the original index name its arriving on your indexers as?

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

zafiro
Explorer

Thank you both for your response!

The data originates by a folder containing log files that is monitored by the HF directly. I managed to solve the problem by adding the index name in the etc/apps/SplunkDeloymentServerConfig/inputs.conf file.

livehybrid
SplunkTrust
SplunkTrust

Hi @zafiro 

Is the data originating on the HF or is being sent to the HF from another source?

If its originating on the HF then you should be able to set index=<indexName> in the relevant stanzas of your inputs.conf on the HF. You'll need to restart for this to take affect.

If the data originates somewhere else then you'll need to use props/transforms to re-write the index name based, is it all data arriving on that HF that needs the index changing? What is the original index name its arriving on your indexers as?

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

isoutamo
SplunkTrust
SplunkTrust
As said you could use props+transforms or ingest actions to do this in HF, but it's always better to do this in inputs.conf on UF.
Of course if someone else is managing those UFs and you haven't (or cannot trust) control of those then you must setting index on HF side.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...