Getting Data In
Highlighted

How can I test that a heavy forwarder on a limited subset of endpoints?

New Member

Is there a way to modify a .conf file or a setting on an individual endpoint to only send data to a single heavy forwarder? I am trying to test functionality on small subset of endpoints before adding a heavy forwarder into the server class on the deployment server.

0 Karma
Highlighted

Re: How can I test that a heavy forwarder on a limited subset of endpoints?

Esteemed Legend

Of course! Just put your limited outputs.conf file here on the UF:

$SPLUNK_HOME/etc/system/local/outputs.conf

Then restart Splunk on the UF.

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.