I need to set up an splunk test environment to test out apps before adding them to production environment, also to test out adding new data into new indexes before adding it to production.
We run an splunk enterprise 7.3.1, all in one single instance on a physical server.
My plan for the test environment is to set up a standalone splunk installation with the free 500MB/day license and test the new stuff.
Does any of you have any experience with something similar?
Can I get the universal forwarder on a few servers to send data to two splunk servers, In the docs on the universal forwarder I understand that there is a support for loadbalancing between several indexers, but it seems like it will send to either and not both.
In outputs.conf on the forwarders:
[tcpout]
defaultGroup = prodserver, testserver
[tcpout:prodserver]
server =
[tcpout:testserver]
server =
From the outputs.conf documentation.
"# You can have as many target groups as you want.
In outputs.conf on the forwarders:
[tcpout]
defaultGroup = prodserver, testserver
[tcpout:prodserver]
server =
[tcpout:testserver]
server =
From the outputs.conf documentation.
"# You can have as many target groups as you want.