Getting Data In

Universal Forwarder to Both On Prem and Cloud Instances

LCelley
Explorer

We're starting outline our architecture and how data will flow, and we're looking to forward data to both an on prem dev environment and cloud environment at the same time. Splunk documentation only seems to show how to install to forward to one version or the other.

I do see that you can modify .conf files to clone data to multiple locations, but during install you're still choosing Splunk Cloud or Enterprise. I guess I'm looking for some input on how people with both types of environments at the same time handle their data.

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @LCelley,

you have to configure your outputs.conf for sendind data to both environment.

Obviously in this way you duplicate your license consuption because you index twice the same logs!

At https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad you can find more infos.

Anyway, at https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-same-data-to-multiple-Splunk-Enterpr... you can find my answer to your question.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @LCelley,

you have to configure your outputs.conf for sendind data to both environment.

Obviously in this way you duplicate your license consuption because you index twice the same logs!

At https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad you can find more infos.

Anyway, at https://community.splunk.com/t5/Getting-Data-In/How-to-send-the-same-data-to-multiple-Splunk-Enterpr... you can find my answer to your question.

Ciao.

Giuseppe

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...