Splunk Enterprise

How to forward logs to a third-party system without affecting logs in Splunk

SamYap
Observer

I'm trying to forward logs base on index to a third-party system, and at the same time, I still need to retain the logs in Splunk. I've tried adding tcpout in outputs.conf, but it only pushing all logs to the third-party system, and doesn't store logs into Splunk. Unable to search new log in Splunk.

[tcpout]

defaultGroup=index1

 

[tcpout:index1]

sendCookedData=false (tried with and without this, both doesn't work)

server=1.1.1.1:12468

Labels (1)
0 Karma

burwell
SplunkTrust
SplunkTrust

Have a look at Replicate a subset of data to a third-party system

You can modify it and do something like this

props.conf
[your-sourcetype-here]
TRANSFORMS-routing = routeAll

transforms.conf
[routeAll]
REGEX=(.)
DEST_KEY=_TCP_ROUTING
FORMAT=yourIndexer,ThirdParty

outputs.conf
[tcpout]
defaultGroup=nothing

[tcpout:yourIndexer]
disabled=false
server=10.1.12.1:9997

[tcpout:ThirdParty]
disabled=false
sendCookedData=false
server=10.1.12.2:1234

 

isoutamo
SplunkTrust
SplunkTrust
Please remember that if any target will be stuck then another targets blocks as soon as queues on first / blocked target are full.
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...