data routing

noun or verb

Data routing is a data distribution method in which one Splunk server determines which data to forward to one or more receiving Splunk servers based on data content. For example, in a situation where one forwarder is sending data to two receivers, with data routing the forwarder matches conditions based on patterns in the event data to selectively send some data to one of the receivers and the rest of the data to the other receiver.

Data routing can also be used to send event data to specific queues, indexes, or third-party systems.

Data routing can be used in conjunction with cloning and load balancing.

For more information

In the Distributed Deployment Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time