<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Will configuring a Universal forwarder to send the same logs to two different Splunk instances cause performance issues? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Will-configuring-a-Universal-forwarder-to-send-the-same-logs-to/m-p/289661#M55260</link>
    <description>&lt;P&gt;No particular performance issues, just double network traffic.&lt;BR /&gt;
But remember that with cloning if one destination is not available, it will pause all forwarding.&lt;/P&gt;</description>
    <pubDate>Fri, 06 Oct 2017 19:23:00 GMT</pubDate>
    <dc:creator>yannK</dc:creator>
    <dc:date>2017-10-06T19:23:00Z</dc:date>
    <item>
      <title>Will configuring a Universal forwarder to send the same logs to two different Splunk instances cause performance issues?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Will-configuring-a-Universal-forwarder-to-send-the-same-logs-to/m-p/289660#M55259</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;We are planning to configure a universal forwarder to send logs to two different Splunk instances i.e.to clone data.&lt;/P&gt;

&lt;P&gt;Configuration we are going to use is,&lt;/P&gt;

&lt;P&gt;In outputs.conf&lt;/P&gt;

&lt;P&gt;[tcpout]&lt;BR /&gt;
defaultGroup = default-autolb-group&lt;/P&gt;

&lt;P&gt;[tcpout:indexer1]&lt;BR /&gt;
server=A.A.A.A:9997, B.B.B.B:9997&lt;/P&gt;

&lt;P&gt;[tcpout:indexer2]&lt;BR /&gt;
server=C.C.C.C:9997 D.D.D.D:9997&lt;/P&gt;

&lt;P&gt;In inputs.conf &lt;/P&gt;

&lt;P&gt;[default] &lt;BR /&gt;
_TCP_ROUTING = *&lt;/P&gt;

&lt;P&gt;I just need to confirm, but will this cause performance issues on the server where the UF is installed?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:07:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Will-configuring-a-Universal-forwarder-to-send-the-same-logs-to/m-p/289660#M55259</guid>
      <dc:creator>nabhosal</dc:creator>
      <dc:date>2020-09-29T16:07:14Z</dc:date>
    </item>
    <item>
      <title>Re: Will configuring a Universal forwarder to send the same logs to two different Splunk instances cause performance issues?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Will-configuring-a-Universal-forwarder-to-send-the-same-logs-to/m-p/289661#M55260</link>
      <description>&lt;P&gt;No particular performance issues, just double network traffic.&lt;BR /&gt;
But remember that with cloning if one destination is not available, it will pause all forwarding.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2017 19:23:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Will-configuring-a-Universal-forwarder-to-send-the-same-logs-to/m-p/289661#M55260</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2017-10-06T19:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: Will configuring a Universal forwarder to send the same logs to two different Splunk instances cause performance issues?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Will-configuring-a-Universal-forwarder-to-send-the-same-logs-to/m-p/289662#M55261</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Thanks  for your help.&lt;BR /&gt;
As per your comment with cloning if one destination is not available, it will pause all forwarding, does it mean if one group is not reachable UF will stop forwarding to other also?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 08:02:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Will-configuring-a-Universal-forwarder-to-send-the-same-logs-to/m-p/289662#M55261</guid>
      <dc:creator>nabhosal</dc:creator>
      <dc:date>2017-10-09T08:02:49Z</dc:date>
    </item>
  </channel>
</rss>

