Splunk Search

How to let Intermediate Forwarder redirect some events to each indexer ?

sieutruc
Contributor

Hello,

I would like to add one intermediate Forwarder between UF(Universal Forwarder) and 2 indexer.
For ex: i want event 1 to go from UF 1,2,3 to index Example in indexer 1, and event 2 from UF 2,3 to index Example 2 in indexer 2.

Normally, i can configure if UFs and indexers are connected directly by using output.conf in each UF. But if there is intermediate Forwarder, how can i configure that forwarder will do all the same things i said ?
Can you give me one example for that ?

(i don't want to use AutoBL and my intermediate Forwarder is heavy Forwarder)

Tags (1)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi sieutruc

setup your heavy forwarder to accept splunktcp and then setup output routing on the heavy forwarder. read more about routing to different indexers in the docs @ http://docs.splunk.com/Documentation/Splunk/4.3.4/Deploy/Routeandfilterdatad#Route_inputs_to_specifi...

hope this helps to get you started with data routing.

cheers,

MuS

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...