Splunk Search

How to let Intermediate Forwarder redirect some events to each indexer ?

sieutruc
Contributor

Hello,

I would like to add one intermediate Forwarder between UF(Universal Forwarder) and 2 indexer.
For ex: i want event 1 to go from UF 1,2,3 to index Example in indexer 1, and event 2 from UF 2,3 to index Example 2 in indexer 2.

Normally, i can configure if UFs and indexers are connected directly by using output.conf in each UF. But if there is intermediate Forwarder, how can i configure that forwarder will do all the same things i said ?
Can you give me one example for that ?

(i don't want to use AutoBL and my intermediate Forwarder is heavy Forwarder)

Tags (1)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi sieutruc

setup your heavy forwarder to accept splunktcp and then setup output routing on the heavy forwarder. read more about routing to different indexers in the docs @ http://docs.splunk.com/Documentation/Splunk/4.3.4/Deploy/Routeandfilterdatad#Route_inputs_to_specifi...

hope this helps to get you started with data routing.

cheers,

MuS

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...