<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Configure an app to target a specific splunk server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Configure-an-app-to-target-a-specific-splunk-server/m-p/524265#M88517</link>
    <description>&lt;P&gt;I have two servers (all-in-one), one's production the other development. Sometimes, I'd like to have a forwarder send data to both. The app from production sends the usual data to &lt;STRONG&gt;just the production server&lt;/STRONG&gt;. Is there a way to limit the app's scope when an app is deployed from development? Right now, it's sending data from the development app to the production server.&lt;/P&gt;</description>
    <pubDate>Mon, 12 Oct 2020 19:08:36 GMT</pubDate>
    <dc:creator>tmontney</dc:creator>
    <dc:date>2020-10-12T19:08:36Z</dc:date>
    <item>
      <title>Configure an app to target a specific splunk server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-an-app-to-target-a-specific-splunk-server/m-p/524265#M88517</link>
      <description>&lt;P&gt;I have two servers (all-in-one), one's production the other development. Sometimes, I'd like to have a forwarder send data to both. The app from production sends the usual data to &lt;STRONG&gt;just the production server&lt;/STRONG&gt;. Is there a way to limit the app's scope when an app is deployed from development? Right now, it's sending data from the development app to the production server.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 19:08:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-an-app-to-target-a-specific-splunk-server/m-p/524265#M88517</guid>
      <dc:creator>tmontney</dc:creator>
      <dc:date>2020-10-12T19:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: Configure an app to target a specific splunk server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-an-app-to-target-a-specific-splunk-server/m-p/524326#M88521</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/159131"&gt;@tmontney&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'm not sure to have understood your need.&lt;/P&gt;&lt;P&gt;Anyway, if you have the DS you can have on the Forwarders only the apps from the DS, this means that there isn't any difference in scope related to the DS, it depends only on the deployed Apps (or better TAs if you're speaking of Forwarders).&lt;/P&gt;&lt;P&gt;So If you want to limit the scope of a data flow , you have two ways:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;if the scope limitation is the number of inputs, in the TA you can configure your inputs to send data to both the servers or only to the production one;&lt;/LI&gt;&lt;LI&gt;if instead you want to send to development server only a part of logs, you can do this only on the production server, but it isn't easy, e.g. you could schedule an alert with a search that sends the results to the development server e.g. by syslog.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Anyway dubbing logs you have a double license consuption!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 06:43:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-an-app-to-target-a-specific-splunk-server/m-p/524326#M88521</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-10-13T06:43:47Z</dc:date>
    </item>
  </channel>
</rss>

