Getting Data In

How can I test that a heavy forwarder on a limited subset of endpoints?

wfmseanm
New Member

Is there a way to modify a .conf file or a setting on an individual endpoint to only send data to a single heavy forwarder? I am trying to test functionality on small subset of endpoints before adding a heavy forwarder into the server class on the deployment server.

0 Karma

woodcock
Esteemed Legend

Of course! Just put your limited outputs.conf file here on the UF:

$SPLUNK_HOME/etc/system/local/outputs.conf

Then restart Splunk on the UF.

0 Karma
Get Updates on the Splunk Community!

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

What's New in Splunk Observability - October 2025

What’s New?    We’re excited to announce the latest enhancements to Splunk Observability Cloud and share ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...