Deployment Architecture

Index from one indexer to another (non-clustered)

troyfred
Explorer

Hello,

So I have a rather unique issue that I am really having trouble with. We have a client that has their own splunk system in place. They send their data in a multitude of indexes to the their main indexer, nothing odd there. What we need though is to have a select grouping of indexes sent from their indexer, to our splunk on another network. A suggestion was made to basically query the indexes and toss them into a file then read that as a log. While that is an option I believe will work, it is a little ghetto and also consumes more disk space. Is there a native way of after something is indexed, for the indexer to also forward it on to us? I talked with our client about having the universal forwarder on the devices send to both indexers (which was way easy but they do not want the network bandwidth on those systems taxed more than they already are), so here I am trying to find the best method to do this. Thanks in advance for any possible assistance.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...