Deployment Architecture

Can I forward the same log files on the Forwarder to two different Splunk Enterprise?

lctanlc
New Member

On the WEB01 and WEB02 servers, I have installed Splunk Forwarder and successfully forwarded the following log files to a APP server that was installed with Splunk Enterprise:

On WEB01 server, D:\log\application1.log
On WEB01 server, D:\log\application2.log
On WEB02 server, D:\log\application1.log
On WEB02 server, D:\log\application2.log

I am now being told to also forward these files to another ENT server, which was installed with a later version of Splunk Enterprise. May I know how should I go about doing such without impacting the original forwarding to the APP server?

Tags (1)
0 Karma

gjanders
SplunkTrust
SplunkTrust

aakwah's answer is valid, I'm just providing some official links.

Data Cloning in the splexicon and/or also refer to the configure data cloning section of outputs.conf

0 Karma

aakwah
Builder

Hello,

In outputs.conf of forwarders, you can have something like this:

[tcpout]
defaultGroup=indexer1,indexer2

[tcpout:indexer1]
server=10.1.1.197:9997

[tcpout:indexer2]
server=10.1.1.200:9997

Regards

0 Karma

lctanlc
New Member

Hi! Will I need to restart anything for the modified outputs.conf file to take effect on the forwarders? How do I go about restarting it?

0 Karma

ggssa2000
Explorer

go to the cmd line and type: $SPLUNK_HOME/bin/splunk restart

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...