Hi All,
I have installed the Unix TA onto a Universal Forwarder and am wanting its results be send to two independent indexers.
I have installed the Unix TA on a universal forwarder and activated it.
Tow send the same data to two indexers you use defaultGroup in outputs.conf from the documentation
http://docs.splunk.com/Documentation/Splunk/6.1.2/Admin/Outputsconf
So I have the following configs but the data is still only appearing at the indexer1 and not the indexer2.
vi /opt/splunkforwarder/etc/system/local/outputs.conf
[tcpout]
defaultGroup=indexer1,indexer2
[tcpout:indexer1]
server=10.10.10.10:9997
compressed=true
[tcpout:indexer2]
server=10.10.10.12:9997
compressed=true
inputs.conf in system probably not important for this but I thought I would include it for completeness. This works btw and the data goes to the correct indexers.
vi /opt/splunkforwarder/etc/system/local/inputs.conf
[default]
host = forwarder1
[monitor:///var/log/info.log]
disabled = false
followTail = 0
host = forwarder1
sourcetype = holdingRegisters
_TCP_ROUTING = indexer1
[monitor:///var/log/info-alt.log]
disabled = false
followTail = 0
host = forwarder1
sourcetype = holdingRegisters
_TCP_ROUTING = indexer2
Simple error. I didn't have the app installed on indexer2 which means that the index did not exist for the Unix TA. So the data had nowhere to go.
Installed the app and everything is working as expected.
Simple error. I didn't have the app installed on indexer2 which means that the index did not exist for the Unix TA. So the data had nowhere to go.
Installed the app and everything is working as expected.