Splunk Search

How to let Intermediate Forwarder redirect some events to each indexer ?

sieutruc
Contributor

Hello,

I would like to add one intermediate Forwarder between UF(Universal Forwarder) and 2 indexer.
For ex: i want event 1 to go from UF 1,2,3 to index Example in indexer 1, and event 2 from UF 2,3 to index Example 2 in indexer 2.

Normally, i can configure if UFs and indexers are connected directly by using output.conf in each UF. But if there is intermediate Forwarder, how can i configure that forwarder will do all the same things i said ?
Can you give me one example for that ?

(i don't want to use AutoBL and my intermediate Forwarder is heavy Forwarder)

Tags (1)
0 Karma

MuS
Legend

Hi sieutruc

setup your heavy forwarder to accept splunktcp and then setup output routing on the heavy forwarder. read more about routing to different indexers in the docs @ http://docs.splunk.com/Documentation/Splunk/4.3.4/Deploy/Routeandfilterdatad#Route_inputs_to_specifi...

hope this helps to get you started with data routing.

cheers,

MuS

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...