Hi All,
Is it possible to forward data from 2 different data source to 2 separate instance. below is the example
Cloud instance
FW1(Data SourceA)--> HF1-->Splunk Cloud
On premises Instance
FW1(Data Source B)--> Splunk Instance.
You can not reliable send the data to two destinations from an universal forwarder, but you can clone the event with a transform on the heavy forwarder and sent the clone to another instances.
[clone-events]
REGEX = .
DEST_KEY=_TCP_ROUTING
FORMAT=<new_tcp_routing>
CLONE_SOURCETYPE = <sourcetype>
This creates a copy of event with a new source type