<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk universal forwarder in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-can-i-send-the-same-data-from-one-universal-forwarder-to/m-p/592809#M12122</link>
    <description>&lt;P&gt;You can specify multiple outputs in the outputs.conf file - each event will be sent to all defined outputs. You can also define a load-balancing group there and then the uf will send events in batches to one of the servers from the group. You can combine the approaches and define multiple groups. See the outputs.conf file specification and examples &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.5/Admin/Outputsconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.5/Admin/Outputsconf&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Apr 2022 04:23:55 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2022-04-07T04:23:55Z</dc:date>
    <item>
      <title>How can i send the same data from one universal forwarder to multiple universal forwarder ?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-can-i-send-the-same-data-from-one-universal-forwarder-to/m-p/592803#M12120</link>
      <description>&lt;P&gt;hi all,&lt;/P&gt;
&lt;P&gt;how can i send the same data from one universal forwarder to multiple universal forwarder ?&lt;/P&gt;
&lt;P&gt;is there a way to configure this ? if yes, please tell me the process.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 15:30:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-can-i-send-the-same-data-from-one-universal-forwarder-to/m-p/592803#M12120</guid>
      <dc:creator>super_saiyan</dc:creator>
      <dc:date>2022-04-07T15:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: splunk universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-can-i-send-the-same-data-from-one-universal-forwarder-to/m-p/592809#M12122</link>
      <description>&lt;P&gt;You can specify multiple outputs in the outputs.conf file - each event will be sent to all defined outputs. You can also define a load-balancing group there and then the uf will send events in batches to one of the servers from the group. You can combine the approaches and define multiple groups. See the outputs.conf file specification and examples &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.5/Admin/Outputsconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.5/Admin/Outputsconf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 04:23:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-can-i-send-the-same-data-from-one-universal-forwarder-to/m-p/592809#M12122</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-04-07T04:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: splunk universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-can-i-send-the-same-data-from-one-universal-forwarder-to/m-p/592826#M12127</link>
      <description>&lt;P&gt;it should be the same way you generally forward data to indexing tier&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;[tcpout]
defaultGroup = uf_tier
&lt;BR /&gt;[tcpout:uf_tier]&lt;BR /&gt;server=uf1:9997,uf2:9997,...&amp;nbsp;so&amp;nbsp;on.&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Refer:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Sending-data-from-one-UF-to-other-UF/m-p/403838" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Getting-Data-In/Sending-data-from-one-UF-to-other-UF/m-p/403838&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Forwarding/Configureforwarderswithoutputs.confd#Example" target="_self"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/Forwarding/Configureforwarderswithoutputs.confd#Example&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 05:33:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-can-i-send-the-same-data-from-one-universal-forwarder-to/m-p/592826#M12127</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2022-04-07T05:33:43Z</dc:date>
    </item>
    <item>
      <title>Re: splunk universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-can-i-send-the-same-data-from-one-universal-forwarder-to/m-p/592831#M12129</link>
      <description>&lt;P&gt;As I wrote before - that's just one of the possibilities of intepreting OP's request. This way each event would get forwarded to one of the destinations from the group only. It would not get forwarded to every one of them at the same time.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 06:02:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-can-i-send-the-same-data-from-one-universal-forwarder-to/m-p/592831#M12129</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-04-07T06:02:20Z</dc:date>
    </item>
    <item>
      <title>Re: splunk universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-can-i-send-the-same-data-from-one-universal-forwarder-to/m-p/592832#M12130</link>
      <description>&lt;P&gt;&lt;SPAN&gt;can we transfer the same data from SplunkUF to two different groups?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/172209"&gt;@mayurr98&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 06:06:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-can-i-send-the-same-data-from-one-universal-forwarder-to/m-p/592832#M12130</guid>
      <dc:creator>super_saiyan</dc:creator>
      <dc:date>2022-04-07T06:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: splunk universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-can-i-send-the-same-data-from-one-universal-forwarder-to/m-p/592834#M12131</link>
      <description>&lt;P&gt;As I wrote before - if you define multiple output groups, you can have "parallel" output channels so that each event gets forwarded to all of those groups.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 06:16:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-can-i-send-the-same-data-from-one-universal-forwarder-to/m-p/592834#M12131</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-04-07T06:16:45Z</dc:date>
    </item>
    <item>
      <title>Re: splunk universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-can-i-send-the-same-data-from-one-universal-forwarder-to/m-p/592835#M12132</link>
      <description>&lt;P&gt;thnka you so much for the response.&lt;/P&gt;&lt;P&gt;can you please provide any example stanza&amp;nbsp; ?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 06:18:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-can-i-send-the-same-data-from-one-universal-forwarder-to/m-p/592835#M12132</guid>
      <dc:creator>super_saiyan</dc:creator>
      <dc:date>2022-04-07T06:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: splunk universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-can-i-send-the-same-data-from-one-universal-forwarder-to/m-p/592836#M12133</link>
      <description>&lt;P&gt;Yes you can but it will hit the license meter twice so you need to cautious about that.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;please see below example&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;[tcpout:uf1]
server = xxx.xxx.xxx.xxx:9997
disabled = false
[tcpout-server://xxx.xxx.xxx.xxx:9997]

[tcpout:uf2]
server=yyy.yyy.yyy.yyy:9997
disabled = false
[tcpout-server://yyy.yyy.yyy.yyy:9997]&lt;BR /&gt;&lt;BR /&gt;.&lt;BR /&gt;…&lt;/PRE&gt;</description>
      <pubDate>Thu, 07 Apr 2022 06:19:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-can-i-send-the-same-data-from-one-universal-forwarder-to/m-p/592836#M12133</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2022-04-07T06:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: splunk universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-can-i-send-the-same-data-from-one-universal-forwarder-to/m-p/592840#M12134</link>
      <description>&lt;P&gt;It's not that simple. Splunk counts the licence usage based on raw data that is written to indexes so if the data is in any way modified and/or filtered, the license usage may not be straightforward doubled.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 06:30:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-can-i-send-the-same-data-from-one-universal-forwarder-to/m-p/592840#M12134</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-04-07T06:30:01Z</dc:date>
    </item>
  </channel>
</rss>

