Hello,
we have 2 Splunk platforms and we are using _TCP_ROUTING to forward logs.
System logs from 1st platform indexers are currently logged on themself.
We want to also receive system logs from indexers of the 1st platform on our 2nd platform however there is no default tcpout group on 1st platform indexers.
So should we create default outputs.conf on 1st platform indexers to continue indexing local system logs?
Thanks for your help.