Deployment Architecture

routing assistance config - HEC to multiple envs

Esky73
Builder

i am receiving data via HEC to a SH which then sends to an index tier.

I've like to also send this data to a secondary indexing tier which is a separate env - need some clarification with the config is the section 'Forward data for a single index only' relevant here - will it still index locally ?

http://docs.splunk.com/Documentation/Splunk/7.1.0/Forwarding/Routeandfilterdatad#Perform_selective_i...

[tcpout]
#Disable the current filters from the defaults outputs.conf
forwardedindex.0.whitelist = 
forwardedindex.1.blacklist =
forwardedindex.2.whitelist =

#Forward data for the "myindex" index
forwardedindex.0.whitelist = myindex
Tags (1)
0 Karma

shelde_msearles
New Member

Did this end up working as you expected?

0 Karma

xpac
SplunkTrust
SplunkTrust

So - you want to send the HEC data to two different destinations?
You sent ALL data from that instance to a certain index tier, by default, and for some data, want to also send that data to a second destination?

0 Karma

Esky73
Builder

hey xpac - correct.

It's not an ideal scenario - just a workaround to send the HEC data to another test env.

0 Karma
Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...