Installation

How to input data into: Multiple enterprise instances (different indexer & index configuration via Universal Forwarder

soumyajk
Engager

I am trying to install a newer version of Splunk enterprise.
As part of this, I want the universal forwarders to forward data to both new and old Splunk enterprise - Indexer masters.

Is there a way to do it?
The new Splunk will have different indexes configured, while the old Splunk should not get affected which has its own indexes.

I read about 2 options
1. Multiple UF on the same machine (this is not supported by Splunk)
2. Cloning data in 

transforms.conf

and sending the cloned data to new Splunk, to the index I want.

Labels (2)
0 Karma

soumyajk
Engager

Can anyone confirm if the below will work?

I have created a new index = test_index in SPLUNK 2 (new)

In the master-apps I have added transforms and props asking to override the data coming in and assigning to the new index.
transforms.conf
[test_index]
REGEX= Have to create appropriate regex for # optional as it is . By default, and I want all data to go to new index
FORMAT = test_index# index name to which we are sending data
DEST_KEY = MetaData:Index # specifying to store the value in FORMAT as index name

props.conf
[host:: abc.cdef.rr]
TRANSFORMS-index = test_index

I will have to add more in props.conf as I add the hosts. Please share thoughts. Much appreciated
Thanks

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...