Getting Data In

Multiple monitor stanzas with wildcard and single file in inputs.conf

splunkreal
Motivator

Hello,

is it possible to have mydirectory\*.log monitor stanza to route data to usual indexers (or any specific monitor stanza) AND another specific mydirectory\file.log to another specific _TCP_ROUTING ?

Thanks.

 

* If this helps, please upvote or accept solution 🙂 *
Labels (5)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Yep, I'm pretty sure. If you "overlap" the same file within two separate stanzas it will get monitored only once.

gcusello
SplunkTrust
SplunkTrust

Hi @splunkreal ,

it shoudl be possible using two _TCP_ROUTING items in the inputs.conf pointing to the two different destinations, obviously in different Indexers.

but in this way you pay twice the license because data is indexed twice.

for more infos see at https://docs.splunk.com/Documentation/Splunk/9.1.1/Forwarding/Routeandfilterdatad#Route_inputs_to_sp... 

Ciao.

Giuseppe

splunkreal
Motivator

Hi @gcusello  great thanks, however may it work if we set different index for the secondary stanza?

* If this helps, please upvote or accept solution 🙂 *
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @splunkreal ,

for my knowledge different Indexers, not indexes.

There's no sense to duplicate logs in two indexes of the same Indexers.

But you have to set the same index name beacuse you really set on index in the input stanza.

If you want to have a different index name on the second Indexers, you have to override this value on it. 

Ciao.

Giuseppe

PickleRick
SplunkTrust
SplunkTrust

I don't think you can monitor the same "base path" twice.

An ugly hack to walk around that is to use (hard/soft) links

0 Karma

splunkreal
Motivator

Are you sure? The stanza is different yet... or we must detail all monitored logs?

Thanks! 🙂

* If this helps, please upvote or accept solution 🙂 *
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...