Deployment Architecture

Prevent forwarder from re forwarding

nicolasbussiere
New Member

We have data being forwarded (heavy forwarder) to a spunk server 1 , and we also forward (heavy forwarder) from that splunk server 1 to an other splunk server 2.

Is there a way to filter out forwarded messages so messages forwarded to server 1 are not sent to server 2 ?

Thanks for any hints !

Tags (2)
0 Karma

renjith_nair
Legend

Do you mean to say splunk server1 is an indexer too?

Anyway try this link to filter or route your data

http://docs.splunk.com/Documentation/Splunk/6.3.1511/Forwarding/Routeandfilterdatad

Happy Splunking!

renjith_nair
Legend

Let me know if it helped!

Happy Splunking!
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...