Getting Data In
Highlighted

Can we have the same source forwarding data to two different Splunk infrastructures?

Communicator

As part of the upgrade we are planning to deploy Splunk 6.3 on a new set of physical servers.
We have around 217 forwarders sending data in the existing infrastructure.
Can we have the forwarders configured to send data to the existing infrastructure as well as the new 6.3 enterprise cluster?

The thought behind this is to have existing infrastructure intact while we upgrade the new infrastructure.

0 Karma
Highlighted

Re: Can we have the same source forwarding data to two different Splunk infrastructures?

SplunkTrust
SplunkTrust

Hi athorat,

yes, this can be configured in outputs.conf

# Clone events to groups indexer1 and indexer2. 
[tcpout:indexer1]
server=Y.Y.Y.Y:9997

[tcpout:indexer2]
server=X.X.X.X:9997

Hope this help ...

cheers, MuS

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.