Deployment Architecture

Forward indexed logs from an Indexer Cluster to a third party system

TodaErika
New Member

Hi Fellow Splunkers,

I am looking to forward all Indexed data from an Indexer Cluster to another third party system. I have read through many posts that suggest configuring a single instance of an Indexer to forward logs cool no problem just follow the guide on "Forward data to third-party systems". However forwarding logs from an Indexer Cluster would be a different ball game right? As different data sits on different indexers in a cluster.

So assuming I have 3 peers that is configured with a Search Factor = 2 and Replication factor of 2. Which Indexer do I choose to forward the logs / what's the best practice? Do I need to add a Heavy Fowarder?

Many thanks!

Labels (3)
0 Karma

ssadh_splunk
Splunk Employee
Splunk Employee

In case this is a one time operation, maybe instead of forwarding the data from index cluster, you can configure the system to read the data off the Splunk deployment, maybe via a REST call. or write a script to read data in small batches with incremental time going back in the past from where you need to start up to current time.
For the incoming data, you can configure a Forwarder to send to this 3rd party system.

0 Karma

TodaErika
New Member

Apologies for the late reply. Thanks for the response.
Unfortunately this is not a one time operation. The data has to be continuously piped to the third-party system. There are multiple WAN sites sending data to the indexer via Heavy Forwarders. I have thought of the possibility of configuring all the Heavy Forwarders to send a duplicate to the third party, but this will cause a upsurge in WAN bandwidths which is not ideal at the moment. The scripts are a great idea, I will look into it perhaps scheduling one that reads periodically.

0 Karma

willsy
Communicator

Hey mate, just wondering how you got along with this? im having the same issue at the moment, i have multiple sites and multiple clustered indexers needing to send to one specific indexer. 

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...