Splunk Enterprise

Is it possible for a heavy forwarder to clone the data to a 9997/tcp output (S2S) and a 8088/tcp httpout (HEC)?

jariw
Path Finder

L.s.,

Is it possible for a heavy forwarder to clone the data to a 9997/tcp output (S2S) and a 8088/tcp httpout (HEC)? So both will recieve the same events.

We have a heavy wich has to send the data to two clusters.  One of these clusters we want the data to be recieved by HEC, the other only has S2S.

thanks in advance

Grts  

Jari

Tags (2)
0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

As @isoutamo said - you can route events and push them into many outputgroups at the same time.

But.

Contrary to what the outputs.conf might suggest, the httpout output while using HEC tokens doesn't really send using HEC. It sends data to the s2s endpoint using s2s protocol embedded within HTTP.

View solution in original post

jariw
Path Finder

Thanks for the answer.

So it doesn't matter if the target is a s2s 9997/tcp target and a 8088 Hec target at the same time? 

grts

Jari

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

As @isoutamo said - you can route events and push them into many outputgroups at the same time.

But.

Contrary to what the outputs.conf might suggest, the httpout output while using HEC tokens doesn't really send using HEC. It sends data to the s2s endpoint using s2s protocol embedded within HTTP.

isoutamo
SplunkTrust
SplunkTrust

Hi

I'm not sure what you are exactly asking 😞

You could route and filter incoming events and forward those to different targets. Just use separate targets on outputs.conf and route events based on something with props and transforms.conf. Here is more about how to do it https://docs.splunk.com/Documentation/Splunk/9.1.0/Forwarding/Routeandfilterdatad

r. Ismo

Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...