Splunk Enterprise

Heavy forwarder does not forward right index from db connect 3

dailv1808
Path Finder

Hi Splunker,

I'm installed splunk database connect app 3.5.1 on splunk server as heavy forwader.

I configured forwarding data to index=AAA but it always forward to index=main, i dont know why, someone help me plz. Thanks!

dailv1808_0-1629437904803.png

 

 

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Have you created this index AAA on your indexer(s)? Time by time (at least in some 6 & 7 versions) there was some issues with upper case index names.

r. Ismo

0 Karma

dailv1808
Path Finder

yes. I created index AAA on indexer. AAA is just an example, my actual index is like my_index_aaa 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Did you got anything to this new index?

What MC (monitoring console) is saying about this index, when you are looking it?

0 Karma

dailv1808
Path Finder

Does i need config in data input HTTP EVENT COLLECTOR?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

In normal case installing DBX 3.x will configure HEC locally and you don't need to do anything for it. Of course if you want you can configure it manually e.g. with your normal VIP for HEC, but I prefer that which come with DBX in most cases.

And as you already get those event to splunk, but into wrong index, HEC is working. But it seems that there are somewhere wrongly configured props.conf and/or transform.conf which change the indexes where those events goes. Or for some reason indexers don't recognise your new index, but if those old DBX versions is using it then this is not true at this case.

Can you try "splunk btool props.conf list <sourcetype> --debug" on every node which are part of path from DBX HF to Indexer. If needed check also source and host same way.

r. Ismo

0 Karma

dailv1808
Path Finder

i tried to set sourcetype=dbx2 in HEC, it work, lok. i dont know why.

Anw thanks your response!

0 Karma

dailv1808
Path Finder

I have 3 heavy forwaders, 2 HF installed splunk db connect 2.4.1 it work fine. I create 3th HF and install splunk db 3.5.1 it doesn't work forward right index.

0 Karma

dailv1808
Path Finder

I see this index in both MC and indexes.conf file on deployment-server.

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...