Hi,
I am having trouble for routing the logs(first.txt) to separate index1/2 and second.txt to index3/4.
below are my environment
inputs.conf
[monitor:///home/odelakumar06/first.txt]
disabled = false
host = hf
index = firstone
sourcetype = firstone
_TCP_ROUTING = FirstGroupIndexer
[monitor:///home/odelakumar06/second.txt]
disabled = false
host = hf
index = secondone
sourcetype = secondone
_TCP_ROUTING = SecondGroupIndexer
and my outputs.conf is
[tcpout]
defaultGroup = FirstGroupIndexer,SecondGroupIndexer
[tcpout:FirstGroupIndexer]
disabled = false
server = 34.100.154.111:9997,35.244.6.201:9997
[tcpout:SecondGroupIndexer]
disabled = false
server = 34.100.190.134:9997,34.93.239.18:9997
and i have one SH and i added all the above indexes in SH.
when i search in SH index=firstone, nothing i am getting.
when i see splunkd log getting below errors. Please suggest
@okumar1 Please provide some more information about your architecture. Are the 4 indexer part of one indexer cluster?
no all 4 indexers are standalone only and i have added all these 4 search peers into SH under distributed search. Please guide me