Getting Data In

How can I test that a heavy forwarder on a limited subset of endpoints?

Is there a way to modify a .conf file or a setting on an individual endpoint to only send data to a single heavy forwarder? I am trying to test functionality on small subset of endpoints before adding a heavy forwarder into the server class on the deployment server.

Of course! Just put your limited outputs.conf file here on the UF:


Then restart Splunk on the UF.

