Getting Data In

Universal Forwarder to Both On Prem and Cloud Instances

LCelley
Explorer

We're starting outline our architecture and how data will flow, and we're looking to forward data to both an on prem dev environment and cloud environment at the same time. Splunk documentation only seems to show how to install to forward to one version or the other.

I do see that you can modify .conf files to clone data to multiple locations, but during install you're still choosing Splunk Cloud or Enterprise. I guess I'm looking for some input on how people with both types of environments at the same time handle their data.

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @LCelley,

you have to configure your outputs.conf for sendind data to both environment.

Obviously in this way you duplicate your license consuption because you index twice the same logs!

At https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad you can find more infos.

Anyway, at https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-same-data-to-multiple-Splunk-Enterpr... you can find my answer to your question.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @LCelley,

you have to configure your outputs.conf for sendind data to both environment.

Obviously in this way you duplicate your license consuption because you index twice the same logs!

At https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad you can find more infos.

Anyway, at https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-same-data-to-multiple-Splunk-Enterpr... you can find my answer to your question.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...