Getting Data In

How to get rsyslog data going to two Splunk instances?

David888
Engager

I would like to know if it is possible to have the data that is coming from the rsyslog server into two Splunk instances.

My rsyslog server is filtering all data and whatever does not get caught falls into a catch all. I would like that catch all data to go to the accpt environment.

Do anyone know how I could achieve this?

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

Check out the section titled "Filter and route event data to target groups" in this link:

https://docs.splunk.com/Documentation/Splunk/7.3.0/Forwarding/Routeandfilterdatad

0 Karma
Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...