Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Why am I unable to forward a sourcetype from a heavy forwarder to different locations with my current configuration?

$
0
0
I'm in the process of migrating one environment's data to its new environment. I have specific hosts forwarding data using the [<host>] stanza in props.conf, but am having problems getting a sourcetype stanza to work. Working config: HF sea->atl props.conf [host::SEAFwd1] TRANSFORMS-routing = routeALL, routeTest TZ = US/Eastern transforms.conf [routeALL] REGEX=(.) DEST_KEY = _TCP_ROUTING #FORMAT = Everything FORMAT = default-autolb-group [routeTest] REGEX = . DEST_KEY = _TCP_ROUTING FORMAT = Subsidiary,default-autolb-group outputs.conf [tcpout] defaultGroup = default-autolb-group [tcpout:default-autolb-group] disabled = false server = splidx01.local:9997,splidx02.local:9997,splidx03.local:9997,splidx04.local:9997 [tcpout:Subsidiary] disabled = false server=newfwd1:9997,newfwd2:9997 I'm attempting to add another source (from another heavy forwarder, no less), with less success. Syslog/cisco hf -> sea hf (splclus1q) -> atl Syslog/cisco hf props.conf [(?::){0}cisco:*] TRANSFORMS-routing = routeALL, routeTest TZ = US/Eastern transforms.conf [routeALL] REGEX = (.) DEST_KEY = _TCP_ROUTING FORMAT = default-autolb-group [routeTest] REGEX = . DEST_KEY = _TCP_ROUTING FORMAT = Subsidiary,default-autolb-group outputs.conf [tcpout] defaultGroup = default-autolb-group [tcpout:default-autolb-group] disabled = false server = splidx01.local:9997,splidx02.local:9997,splidx03.local:9997,splidx04.local:9997 [tcpout:Subsidiary] disabled = false server = splclus01q.local:9997 New Sea HF props stanza = [host::\b(SEAFwd1|Syslog/cisco hf) TRANSFORMS-routing = routeALL, routeTest TZ = US/Eastern [(?::){0}cisco:*] TRANSFORMS-routing = routeALL, routeTest TZ = US/Eastern And I'm not seeing the sourcetype in the new environment. Can someone help spot what I'm doing wrong? Thanks.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>