<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can I forward to 2 splunkcloud deployments at a time ? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-forward-to-2-splunkcloud-deployments-at-a-time/m-p/150141#M30528</link>
    <description>&lt;P&gt;I have 1 splunkcloud deployment, and I need to send a copy of my data to another deployment.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;can the splunklcoud indexers forward data  to another deployment ?&lt;/LI&gt;
&lt;LI&gt;can my forwarder send data to both deployments ?&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;I tried to see the forwarder credential apps I have, but they do not play nice together.&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jul 2015 19:13:10 GMT</pubDate>
    <dc:creator>yannK</dc:creator>
    <dc:date>2015-07-30T19:13:10Z</dc:date>
    <item>
      <title>Can I forward to 2 splunkcloud deployments at a time ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-forward-to-2-splunkcloud-deployments-at-a-time/m-p/150141#M30528</link>
      <description>&lt;P&gt;I have 1 splunkcloud deployment, and I need to send a copy of my data to another deployment.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;can the splunklcoud indexers forward data  to another deployment ?&lt;/LI&gt;
&lt;LI&gt;can my forwarder send data to both deployments ?&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;I tried to see the forwarder credential apps I have, but they do not play nice together.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2015 19:13:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-forward-to-2-splunkcloud-deployments-at-a-time/m-p/150141#M30528</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2015-07-30T19:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: Can I forward to 2 splunkcloud deployments at a time ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-forward-to-2-splunkcloud-deployments-at-a-time/m-p/150142#M30529</link>
      <description>&lt;P&gt;After testing here is the procedure to configure a forwarder to send to 2 groups of indexers.&lt;/P&gt;

&lt;P&gt;1- download/retrieve the &lt;STRONG&gt;splunkcloud forwarder credential apps&lt;/STRONG&gt; for the deployment A and B&lt;BR /&gt;
rename the app folder to distinguish them. &lt;BR /&gt;
by example:   splunkcloudforwarder_A  splunkcloudforwarder_B&lt;BR /&gt;
You need to keep them both, as they contains distinct ssl certificates.&lt;/P&gt;

&lt;P&gt;2-   in the app, go to default/outputs.conf&lt;BR /&gt;
and &lt;STRONG&gt;edit the name of the tcpout group&lt;/STRONG&gt; to distinguish them&lt;/P&gt;

&lt;P&gt;[tcpout:primary_indexers]&lt;BR /&gt;
to&lt;BR /&gt;
[tcpout:primary_indexers_A]&lt;BR /&gt;
and&lt;BR /&gt;
[tcpout:primary_indexers_B]&lt;/P&gt;

&lt;P&gt;3 - add a local/outputs.conf in one of the apps ( or in etc/system/local, but it's not convenient to deploy in apps)&lt;BR /&gt;
and &lt;STRONG&gt;put the 2 new groups as default destination groups&lt;/STRONG&gt; to clone the data to both.&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
defaultGroup = primary_indexers_A, primary_indexers_B&lt;/P&gt;

&lt;P&gt;4 - test the merging of the configurations with a &lt;STRONG&gt;btool command&lt;/STRONG&gt;&lt;BR /&gt;
cd $SPLUNK_HOME/bin&lt;BR /&gt;
./splunk cmd btool outputs list&lt;BR /&gt;
You want to see&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
defaultGroup = primary_indexers_A, primary_indexers_B&lt;BR /&gt;
and 2 groups&lt;BR /&gt;
[tcpout:primary_indexers_A]&lt;BR /&gt;
[tcpout:primary_indexers_B]&lt;/P&gt;

&lt;P&gt;if you do not see them, use&lt;BR /&gt;
./splunk cmd btool outputs list --debug&lt;BR /&gt;
to check where each configurations are coming from.&lt;/P&gt;

&lt;P&gt;5- &lt;STRONG&gt;start the forwarder and confirm&lt;/STRONG&gt; that it is sending data to the 2 groups&lt;BR /&gt;
you can look at the internal logs (index=_internal host=myforwardername)&lt;/P&gt;

&lt;P&gt;Remarks :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;when you start splunk, the clear ssl password in the apps /default/outputs.conf will be encrypted and saved in /local/outputs.conf file. But cannot be decrypted by another forwarder. So if you want to copy the apps from a forwarder to another, (or deploy it using a deployment server), make sure to remove the line with the local folder.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;You can use this configuration on the forwarders directly&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;If you want to use intermediary forwarder you just need to configure your first forwarders to send the data to the intermediary forwarders, and setup an input on the intermediary forwarder in inouts.conf&lt;BR /&gt;
[splunktcp:9997]&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;You can use an Universal forwarder or a lightweight forwarder as intermediary forwarder (the heavy forwarder allow parsing and filtering but has a heavier load, and require you to install all your indexers parsing apps on them too)&lt;/LI&gt;
&lt;/UL&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 29 Sep 2020 06:51:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-forward-to-2-splunkcloud-deployments-at-a-time/m-p/150142#M30529</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2020-09-29T06:51:08Z</dc:date>
    </item>
  </channel>
</rss>

