Splunk Search

Having trouble with routing problem with _TCP_ROUTING?

okumar1
Engager

Hi,

I am having trouble for routing the logs(first.txt) to separate index1/2 and second.txt to index3/4.

 

below are my environment

inputs.conf

[monitor:///home/odelakumar06/first.txt]
disabled = false
host = hf
index = firstone
sourcetype = firstone
_TCP_ROUTING = FirstGroupIndexer

[monitor:///home/odelakumar06/second.txt]
disabled = false
host = hf
index = secondone
sourcetype = secondone
_TCP_ROUTING = SecondGroupIndexer

and my outputs.conf is

[tcpout]
defaultGroup = FirstGroupIndexer,SecondGroupIndexer

[tcpout:FirstGroupIndexer]
disabled = false
server = 34.100.154.111:9997,35.244.6.201:9997

[tcpout:SecondGroupIndexer]
disabled = false
server = 34.100.190.134:9997,34.93.239.18:9997

and i have one SH and i added all the above indexes in SH. 

when i search in SH index=firstone, nothing i am getting.

when i see splunkd log getting below errors. Please suggest

 

02-02-2023 06:33:10.051 +0000 ERROR TcpInputProc [1983 FwdDataReceiverThread] - Message rejected. Received unexpected message of size=1195725856 bytes from src=162.142.125.9:49748 in streaming mode. Maximum message size allowed=67108864. (::) Possible invalid source sending data to splunktcp port or valid source sending unsupported payload.
  • host = indx-1
  • source =/opt/splunk/var/log/splunk/splunkd.log
  • sourcetype = splunkd

 

0 Karma

PaulPanther
Motivator

@okumar1 Please provide some more information about your architecture. Are the 4 indexer part of one indexer cluster?

0 Karma

okumar1
Engager

no all 4 indexers are standalone only and i have added all these 4 search peers into SH under distributed search. Please guide me

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...