Splunk Search

UDP input and _TCP_ROUTING - is it possible?

andyk
Path Finder

Is it possible to use _TCP_ROUTING with a UDP input? I can not get it to work. My other "monitor" inputs works fine with _TCP_ROUTING. This is a full forwarder not a lwf.

inputs.conf:

[udp://514]
index = testapp
sourcetype = syslog
_TCP_ROUTING = pnlogGroup

outputs.conf:

[tcpout]
defaultGroup = SlogGroup
disabled = false
indexAndForward = 0

[tcpout:pnlogGroup]
disabled = false
server = 10.0.0.41:9997

[tcpout:SlogGroup]
disabled = false
server = 10.0.0.50:9995
Tags (2)
0 Karma
1 Solution

Masa
Splunk Employee
Splunk Employee

I think you already got answer a looooooong time ago. Answer is yes. A full Forwarder process data and parse events from udp inputs, and send the processed/parsed to Splunk as you configured in outputs.conf.

View solution in original post

kml_uvce
Builder

yes, here you are reciving data via udp but sending data via tcp and both are separated...
-Kamal Bisht

0 Karma

Masa
Splunk Employee
Splunk Employee

What do you mean by "sending data via tcp and both are separated.."?

0 Karma

Masa
Splunk Employee
Splunk Employee

I think you already got answer a looooooong time ago. Answer is yes. A full Forwarder process data and parse events from udp inputs, and send the processed/parsed to Splunk as you configured in outputs.conf.

Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...