Splunk Enterprise

Forwarding events to 2 separate splunk indexers cluster from one HF

jg91
Path Finder

Hello, we Have 2 separate Splunk indexer clusters with 2 separate licenses for each one, can we forward data to both of them from one Heavy Forwarder? what license we should use on the HF?

Labels (1)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

You can copy same events to two or more indexer clusters just adding needed output target groups to outputs.conf. There are examples on documentation how this can done. https://docs.splunk.com/Documentation/Forwarder/8.0.5/Forwarder/Configureforwardingwithoutputs.conf  Configure data cloning on a universal forwarder with outputs.conf

 

Basically it's up to you which license server you want to use with those HFs as HFs don't use your license's capacity, just those features.

r. Ismo

jg91
Path Finder

so there is no restriction to use the same license for the HF and All Indexers (in both clusters) and simply I can use just one of those license masters, is it right?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

basically that way if/when those both clusters are use the same license from the same LM! Another restrictions (at least has had earlier) is that all members must use the same Pass4SymmKey under general stanza on server.conf.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...