Getting Data In

Universal Forwarder to Both On Prem and Cloud Instances

LCelley
Explorer

We're starting outline our architecture and how data will flow, and we're looking to forward data to both an on prem dev environment and cloud environment at the same time. Splunk documentation only seems to show how to install to forward to one version or the other.

I do see that you can modify .conf files to clone data to multiple locations, but during install you're still choosing Splunk Cloud or Enterprise. I guess I'm looking for some input on how people with both types of environments at the same time handle their data.

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @LCelley,

you have to configure your outputs.conf for sendind data to both environment.

Obviously in this way you duplicate your license consuption because you index twice the same logs!

At https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad you can find more infos.

Anyway, at https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-same-data-to-multiple-Splunk-Enterpr... you can find my answer to your question.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @LCelley,

you have to configure your outputs.conf for sendind data to both environment.

Obviously in this way you duplicate your license consuption because you index twice the same logs!

At https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad you can find more infos.

Anyway, at https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-same-data-to-multiple-Splunk-Enterpr... you can find my answer to your question.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...