Splunk Enterprise

Prevent Indexer from indexing whilst forwarding syslog to a 3rd party system

bvv
Explorer

outputs.conf

[syslog:syslogGroup]
server = x.x.x.x:514

props.conf

[helloworld]
TRANSFORMS-rsyslog = syslogRouting

transforms.conf

[syslogRouting]
REGEX = .
DEST_KEY = _SYSLOG_ROUTING
FORMAT = syslogGroup

This config is applied on an indexer (many tutorials use a heavy forwarder which by defaults does not index data). This works perfectly in forwarding rawdata in syslog to another system however rawdata is also being indexed. Is there a way to prevent indexing from happening?

I've tried adding a nullQueue stanza to props.conf without luck.

Tags (1)
0 Karma

masonmorales
Influencer

Is the data already cooked when it hits the indexer? / What's forwarding the data to the indexer?

0 Karma

bvv
Explorer

Data is not not cooked
UF-->This splunk instance (both Indexer and Search Head role)

0 Karma

manjunathmeti
Champion

Set index = false for indexAndForward in outputs.conf.

[indexAndForward]
index=false
0 Karma

bvv
Explorer

This will stop not just [helloworld] but all other indexes from indexing.

The splunk instance itself is an Indexer and a Search Head at the same time.

0 Karma

manjunathmeti
Champion

You can try this. Set selectiveIndexing = true. And remove attribute _INDEX_AND_FORWARD_ROUTING if added under monitor stanza in inputs.conf. This makes forwarder to not index this data.

[indexAndForward]
index=true
selectiveIndexing = true
0 Karma

bvv
Explorer

This stopped indexing on all indexes as well..
I might consider setting up a HF to pick up data from UF instead of sending directly to Indexer.

0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 2)

Welcome to the "Splunk Classroom Chronicles" series, created to help curious, career-minded learners get ...

Index This | I am a number but I am countless. What am I?

January 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  Happy New Year! We’re ...

What’s New in Splunk Enterprise 9.4: Tools for Digital Resilience

PLATFORM TECH TALKS What’s New in Splunk Enterprise 9.4: Tools for Digital Resilience Thursday, February 27, ...