Splunk Enterprise Security

forwarding from index_a to index_b

shahchintant
Engager

If events are coming in from heavy forwarder 1 to heavy forwarder 2, is is possible to change the index name on HF B in inputs.conf ?

for example:
I have source- A sending application-x logs to HF1, those application-x logs are coming in syslog format on port-123 udp,

source-A -------->port xyz/tcp on HF1 (inputs.conf configured to map that port to index_A)-------------->coming on port xyz/tcp to HF2 (define events to go to index_B in inputs.conf for port 321/udp?) ------> indexers (stores logs in index_B).

I want to take those logs and map it to index_B instead of index_A, is it possible???

changing from HF1 is not possible as no control on it.

additional question:

Source is same, 3 event types are coming on 3 indexes:
Source A (index_A1,index_A2,index_A3) on port xyz

Can we change those indexes to:
Source A (index_B1,index_B2,index_B3) on port xyz on HFs?

0 Karma

FrankVl
Ultra Champion

Assuming HF1 is forwarding cooked data to a splunktcp input on HF2, I don't think the regular metadata overriding concepts work. I'm not aware of a way to override metadata fields like the index in cooked data.

Perhaps there is a way to read things from the index A and then write it to index B (and then setting index A to a very low retention time), but that means indexing things twice, which gets rather expensive if this is a significant volume of data.

shahchintant
Engager

yes thank you . It is cooked data. probably cant change index on the fly.

0 Karma

HiroshiSatoh
Champion
0 Karma

FrankVl
Ultra Champion

No, because that has a universal forwarder as the first forwarder.

0 Karma

shahchintant
Engager

yep its not UF its a HF

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...