I have a few servers that have universal forwarders that need to be updated where I can send the Application data to one Splunk environment and the OS logs to another environment. I believe this is possible but just want to know who to get this done. I'm assuming the inputs.conf and outputs.conf need to be updated. Just looking for guidance.
https://www.tekstream.com/blog/route-data-to-multiple-destinations/
You can watch this video if you stuck anywhere
https://www.youtube.com/watch?v=AxHetwfLC0Y