Hello,
I'd like to know whether a Splunk Enterprise deployment can act as a UF to another Splunk Enterprise deployment. What I'd like to do is be able to index and analyze log data using a Splunk Enterprise deployment within a private network, and then send a subset of that data to a Splunk Enterprise cloud deployment. The reasons for this intermediate step are:
Is there a configuration that exists within Splunk Enterprise that enables the forwarding of it's data to a separate Splunk Enterprise deployment, or do I have to use a dedicated UF on the same machine and create saved searches that output CSV files for it to transfer to cloud?
Thank you and best regards,
Andrew
 
					
				
		
Hi,
Have a look at this documentation https://docs.splunk.com/Documentation/Splunk/7.2.5/Forwarding/Routeandfilterdatad
