<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: We want to migrate the App and addon data to splunk cloud from onprem. in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/We-want-to-migrate-the-App-and-addon-data-to-splunk-cloud-from/m-p/743854#M3724</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241326"&gt;@Hemant_h&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The SH should be relatively simple, if you want to send the data from your SH to Cloud then you will just need to install the Universal Forwarder app which you can download from your Splunk Cloud instance onto the SH. However if the SH is already sending it's internal logs elsewhere (e.g. internal Indexers) then this change will likely overwrite this setup, you will need to update your outputs.conf to set the [tcpout]/defaultGroup value to a comma delimited list of your existing output group and the new Splunk Cloud output group.&lt;/P&gt;&lt;P&gt;The same likely applies to your HF - is your HF not currently sending to Splunk Cloud? If it sends elsewhere and you need to maintain this then you will also need to apply the changes to defaultGroup in addition to installing the forwarder app from your Splunk Cloud environment.&lt;/P&gt;&lt;P&gt;For more info check out&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Forwarder/9.4.1/Forwarder/Configureforwardingwithoutputs.conf" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Forwarder/9.4.1/Forwarder/Configureforwardingwithoutputs.conf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt; &lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt; If so, please consider:&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;Adding kudos to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Wed, 09 Apr 2025 09:04:37 GMT</pubDate>
    <dc:creator>livehybrid</dc:creator>
    <dc:date>2025-04-09T09:04:37Z</dc:date>
    <item>
      <title>We want to migrate the App and addon data to splunk cloud from onprem.</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/We-want-to-migrate-the-App-and-addon-data-to-splunk-cloud-from/m-p/743850#M3722</link>
      <description>&lt;P&gt;HI Team,&lt;BR /&gt;what would be best way to send logs of apps and addon installed on onprem HF and sh to cloud enviroment.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 07:49:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/We-want-to-migrate-the-App-and-addon-data-to-splunk-cloud-from/m-p/743850#M3722</guid>
      <dc:creator>Hemant_h</dc:creator>
      <dc:date>2025-04-09T07:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: We want to migrate the App and addon data to splunk cloud from onprem.</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/We-want-to-migrate-the-App-and-addon-data-to-splunk-cloud-from/m-p/743854#M3724</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241326"&gt;@Hemant_h&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The SH should be relatively simple, if you want to send the data from your SH to Cloud then you will just need to install the Universal Forwarder app which you can download from your Splunk Cloud instance onto the SH. However if the SH is already sending it's internal logs elsewhere (e.g. internal Indexers) then this change will likely overwrite this setup, you will need to update your outputs.conf to set the [tcpout]/defaultGroup value to a comma delimited list of your existing output group and the new Splunk Cloud output group.&lt;/P&gt;&lt;P&gt;The same likely applies to your HF - is your HF not currently sending to Splunk Cloud? If it sends elsewhere and you need to maintain this then you will also need to apply the changes to defaultGroup in addition to installing the forwarder app from your Splunk Cloud environment.&lt;/P&gt;&lt;P&gt;For more info check out&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Forwarder/9.4.1/Forwarder/Configureforwardingwithoutputs.conf" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Forwarder/9.4.1/Forwarder/Configureforwardingwithoutputs.conf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt; &lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt; If so, please consider:&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;Adding kudos to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 09 Apr 2025 09:04:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/We-want-to-migrate-the-App-and-addon-data-to-splunk-cloud-from/m-p/743854#M3724</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-04-09T09:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: We want to migrate the App and addon data to splunk cloud from onprem.</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/We-want-to-migrate-the-App-and-addon-data-to-splunk-cloud-from/m-p/743902#M3729</link>
      <description>&lt;P&gt;If you don’t need to send those into onprem too then just add SCP uf package to those and all logs will sent to SCP only.&lt;/P&gt;&lt;P&gt;If you are needing those on both env then you must add that UF and addition transforms or inputs.conf where you are defining which logs goes to SCP and which to onprem and which one to both. But remember that sending those to both means double license usage.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 19:52:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/We-want-to-migrate-the-App-and-addon-data-to-splunk-cloud-from/m-p/743902#M3729</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-04-09T19:52:04Z</dc:date>
    </item>
  </channel>
</rss>

