On the WEB01 and WEB02 servers, I have installed Splunk Forwarder and successfully forwarded the following log files to a APP server that was installed with Splunk Enterprise:
On WEB01 server, D:\log\application1.log
On WEB01 server, D:\log\application2.log
On WEB02 server, D:\log\application1.log
On WEB02 server, D:\log\application2.log
I am now being told to also forward these files to another ENT server, which was installed with a later version of Splunk Enterprise. May I know how should I go about doing such without impacting the original forwarding to the APP server?
aakwah's answer is valid, I'm just providing some official links.
Data Cloning in the splexicon and/or also refer to the configure data cloning section of outputs.conf
Hello,
In outputs.conf of forwarders, you can have something like this:
[tcpout]
defaultGroup=indexer1,indexer2
[tcpout:indexer1]
server=10.1.1.197:9997
[tcpout:indexer2]
server=10.1.1.200:9997
Regards
Hi! Will I need to restart anything for the modified outputs.conf file to take effect on the forwarders? How do I go about restarting it?
go to the cmd line and type: $SPLUNK_HOME/bin/splunk restart