Deployment Architecture

Forward indexed logs from an Indexer Cluster to a third party system

TodaErika
New Member

Hi Fellow Splunkers,

I am looking to forward all Indexed data from an Indexer Cluster to another third party system. I have read through many posts that suggest configuring a single instance of an Indexer to forward logs cool no problem just follow the guide on "Forward data to third-party systems". However forwarding logs from an Indexer Cluster would be a different ball game right? As different data sits on different indexers in a cluster.

So assuming I have 3 peers that is configured with a Search Factor = 2 and Replication factor of 2. Which Indexer do I choose to forward the logs / what's the best practice? Do I need to add a Heavy Fowarder?

Many thanks!

Labels (3)
0 Karma

ssadh_splunk
Splunk Employee
Splunk Employee

In case this is a one time operation, maybe instead of forwarding the data from index cluster, you can configure the system to read the data off the Splunk deployment, maybe via a REST call. or write a script to read data in small batches with incremental time going back in the past from where you need to start up to current time.
For the incoming data, you can configure a Forwarder to send to this 3rd party system.

0 Karma

TodaErika
New Member

Apologies for the late reply. Thanks for the response.
Unfortunately this is not a one time operation. The data has to be continuously piped to the third-party system. There are multiple WAN sites sending data to the indexer via Heavy Forwarders. I have thought of the possibility of configuring all the Heavy Forwarders to send a duplicate to the third party, but this will cause a upsurge in WAN bandwidths which is not ideal at the moment. The scripts are a great idea, I will look into it perhaps scheduling one that reads periodically.

0 Karma

willsy
Communicator

Hey mate, just wondering how you got along with this? im having the same issue at the moment, i have multiple sites and multiple clustered indexers needing to send to one specific indexer. 

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...