- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to forward logs to a third-party system without affecting logs in Splunk
SamYap
Observer
02-28-2024
07:43 PM
I'm trying to forward logs base on index to a third-party system, and at the same time, I still need to retain the logs in Splunk. I've tried adding tcpout in outputs.conf, but it only pushing all logs to the third-party system, and doesn't store logs into Splunk. Unable to search new log in Splunk.
[tcpout]
defaultGroup=index1
[tcpout:index1]
sendCookedData=false (tried with and without this, both doesn't work)
server=1.1.1.1:12468
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

burwell

SplunkTrust
02-28-2024
09:44 PM
Have a look at Replicate a subset of data to a third-party system
You can modify it and do something like this
props.conf
[your-sourcetype-here]
TRANSFORMS-routing = routeAll
transforms.conf
[routeAll]
REGEX=(.)
DEST_KEY=_TCP_ROUTING
FORMAT=yourIndexer,ThirdParty
outputs.conf
[tcpout]
defaultGroup=nothing
[tcpout:yourIndexer]
disabled=false
server=10.1.12.1:9997
[tcpout:ThirdParty]
disabled=false
sendCookedData=false
server=10.1.12.2:1234
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
isoutamo

SplunkTrust
03-01-2024
09:26 AM
Please remember that if any target will be stuck then another targets blocks as soon as queues on first / blocked target are full.
