Quantcast
Channel: Questions in topic: "heavy-forwarder"
Viewing all articles
Browse latest Browse all 727

From a Heavy Forwarder to an Indexer, how can I get Splunk to separate Windows and Linux logs into two different indexes?

$
0
0
So my issue is that I am not sure how to get Splunk to separate data on the indexer. I am trying to listen on the forwarder port 514 (for Linux syslog) and 6161 (for windows event logs), I use _tcp_routing to send it to a tcpout targetgroup associated with the indexer ports 9997, and 9998. which allows me to have a splunktcp:// index= for each port. Am I doing this all wrong, and how can I get Splunk to separate the windows and Linux logs into two different indexes? ~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Forwarder: fwd inputs.conf- [scripts://$SPLUNK_HOME\bin\scripts\splunk-wmi.path] disabled=0 [tcp://514] _TCP_ROUTING=Linux [tcp://6161] _TCP_ROUTING=Windows ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ fwd outputs.conf - [tcpout] defaultGroup=Windows, Linux [tcpout:Windows] server=(server ip):9997 [tcpout:Linux] server=(server ip):9998 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ indexer: index inputs.conf - [default] host = somehost1 [tcp://9997] index=windowseventlogs connection_host=dns [tcp://9998] index=linuxauditlogs connection_host=dns

Viewing all articles
Browse latest Browse all 727

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>