Splunk Search

Indexed data redirection

soe_hlawin
Explorer

I want to redirection the indexed data into separate index through transforms.conf

  1. Post redirection, does the data available in both the indexes or only the new index?
  2. Does this redirection consume double the space which ulimately doulbes my licensing cost?
Tags (2)
0 Karma
1 Solution

Ayn
Legend

The redirection is a pure redirection, i.e. the data will go to the index you've redirected it to only. So, because it's only going to one index, there's no impact on licensing as you're still indexing the same amount of data.

View solution in original post

0 Karma

Ayn
Legend

The redirection is a pure redirection, i.e. the data will go to the index you've redirected it to only. So, because it's only going to one index, there's no impact on licensing as you're still indexing the same amount of data.

0 Karma

soe_hlawin
Explorer

Ayn, Thanks for clarification. Is there a way to manipulate at indexer lever to have the data in two different indexes?
My usecase is to have a index with actual data and another with same data but masked values.

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...