<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Heavy forwarder logs - Splunk Cloud &amp;amp; Test Indexers in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-logs-Splunk-Cloud-amp-Test-Indexers/m-p/649088#M110310</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I wanted to forward my logs from heavy forwarder to Splunk Cloud and the same logs should forward to my test indexers as well.&lt;/P&gt;&lt;P&gt;Now the configurations exists to forward the logs to Splunk cloud indexers and how to configure the same logs to forward to test indexers.&lt;/P&gt;&lt;P&gt;Where do we configure the outputs.conf and how do we&amp;nbsp; configure.&lt;/P&gt;&lt;P&gt;Is there a possibility&amp;nbsp; for this type of requirement.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please do let us know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards,&lt;/P&gt;&lt;P&gt;Umesh&lt;/P&gt;</description>
    <pubDate>Tue, 04 Jul 2023 10:37:28 GMT</pubDate>
    <dc:creator>umesh</dc:creator>
    <dc:date>2023-07-04T10:37:28Z</dc:date>
    <item>
      <title>Heavy forwarder logs - Splunk Cloud &amp; Test Indexers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-logs-Splunk-Cloud-amp-Test-Indexers/m-p/649088#M110310</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I wanted to forward my logs from heavy forwarder to Splunk Cloud and the same logs should forward to my test indexers as well.&lt;/P&gt;&lt;P&gt;Now the configurations exists to forward the logs to Splunk cloud indexers and how to configure the same logs to forward to test indexers.&lt;/P&gt;&lt;P&gt;Where do we configure the outputs.conf and how do we&amp;nbsp; configure.&lt;/P&gt;&lt;P&gt;Is there a possibility&amp;nbsp; for this type of requirement.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please do let us know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards,&lt;/P&gt;&lt;P&gt;Umesh&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jul 2023 10:37:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-logs-Splunk-Cloud-amp-Test-Indexers/m-p/649088#M110310</guid>
      <dc:creator>umesh</dc:creator>
      <dc:date>2023-07-04T10:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy forwarder logs - Splunk Cloud &amp; Test Indexers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-logs-Splunk-Cloud-amp-Test-Indexers/m-p/649091#M110311</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249929"&gt;@umesh&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;here you can find the configuration to send your logs to two different indexers groups:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.5/Forwarding/Routeandfilterdatad#Filter_and_route_event_data_to_target_groups" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.5/Forwarding/Routeandfilterdatad#Filter_and_route_event_data_to_target_groups&lt;/A&gt;&lt;/P&gt;&lt;P&gt;in addition, in this url I answered to the same question of another people and you can take the needed information:&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Deployment-Architecture/Is-there-a-way-for-HF-double-forward-to-Splunk-On-Prem-and-Cloud/m-p/648171#M27231" target="_blank"&gt;https://community.splunk.com/t5/Deployment-Architecture/Is-there-a-way-for-HF-double-forward-to-Splunk-On-Prem-and-Cloud/m-p/648171#M27231&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jul 2023 10:53:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-logs-Splunk-Cloud-amp-Test-Indexers/m-p/649091#M110311</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-07-04T10:53:59Z</dc:date>
    </item>
  </channel>
</rss>

