Getting Data In

How can I test that a heavy forwarder on a limited subset of endpoints?

wfmseanm
New Member

Is there a way to modify a .conf file or a setting on an individual endpoint to only send data to a single heavy forwarder? I am trying to test functionality on small subset of endpoints before adding a heavy forwarder into the server class on the deployment server.

0 Karma

woodcock
Esteemed Legend

Of course! Just put your limited outputs.conf file here on the UF:

$SPLUNK_HOME/etc/system/local/outputs.conf

Then restart Splunk on the UF.

0 Karma
Get Updates on the Splunk Community!

Alpha Launch: AI-Assisted Auto-Schematization for CIM

Streamlining Data Onboarding: Announcing the Alpha Release of AI-Assisted Auto-Schematization For many Splunk ...

Enterprise Security(ES) Essentials or Premier? Let's discuss Splunk ES Editions on ...

  Hi everyone, Last year at .conf25, we shared something exciting: Splunk Enterprise Security is evolving ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 5

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...