Splunk Enterprise

Forwarding events to 2 separate splunk indexers cluster from one HF

jg91
Path Finder

Hello, we Have 2 separate Splunk indexer clusters with 2 separate licenses for each one, can we forward data to both of them from one Heavy Forwarder? what license we should use on the HF?

Labels (1)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

You can copy same events to two or more indexer clusters just adding needed output target groups to outputs.conf. There are examples on documentation how this can done. https://docs.splunk.com/Documentation/Forwarder/8.0.5/Forwarder/Configureforwardingwithoutputs.conf  Configure data cloning on a universal forwarder with outputs.conf

 

Basically it's up to you which license server you want to use with those HFs as HFs don't use your license's capacity, just those features.

r. Ismo

jg91
Path Finder

so there is no restriction to use the same license for the HF and All Indexers (in both clusters) and simply I can use just one of those license masters, is it right?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

basically that way if/when those both clusters are use the same license from the same LM! Another restrictions (at least has had earlier) is that all members must use the same Pass4SymmKey under general stanza on server.conf.

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...