Splunk Enterprise

Heavy forwarder does not forward right index from db connect 3

dailv1808
Path Finder

Hi Splunker,

I'm installed splunk database connect app 3.5.1 on splunk server as heavy forwader.

I configured forwarding data to index=AAA but it always forward to index=main, i dont know why, someone help me plz. Thanks!

dailv1808_0-1629437904803.png

 

 

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Have you created this index AAA on your indexer(s)? Time by time (at least in some 6 & 7 versions) there was some issues with upper case index names.

r. Ismo

0 Karma

dailv1808
Path Finder

yes. I created index AAA on indexer. AAA is just an example, my actual index is like my_index_aaa 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Did you got anything to this new index?

What MC (monitoring console) is saying about this index, when you are looking it?

0 Karma

dailv1808
Path Finder

Does i need config in data input HTTP EVENT COLLECTOR?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

In normal case installing DBX 3.x will configure HEC locally and you don't need to do anything for it. Of course if you want you can configure it manually e.g. with your normal VIP for HEC, but I prefer that which come with DBX in most cases.

And as you already get those event to splunk, but into wrong index, HEC is working. But it seems that there are somewhere wrongly configured props.conf and/or transform.conf which change the indexes where those events goes. Or for some reason indexers don't recognise your new index, but if those old DBX versions is using it then this is not true at this case.

Can you try "splunk btool props.conf list <sourcetype> --debug" on every node which are part of path from DBX HF to Indexer. If needed check also source and host same way.

r. Ismo

0 Karma

dailv1808
Path Finder

i tried to set sourcetype=dbx2 in HEC, it work, lok. i dont know why.

Anw thanks your response!

0 Karma

dailv1808
Path Finder

I have 3 heavy forwaders, 2 HF installed splunk db connect 2.4.1 it work fine. I create 3th HF and install splunk db 3.5.1 it doesn't work forward right index.

0 Karma

dailv1808
Path Finder

I see this index in both MC and indexes.conf file on deployment-server.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...