Splunk Enterprise

Forwarding events to 2 separate splunk indexers cluster from one HF

jg91
Path Finder

Hello, we Have 2 separate Splunk indexer clusters with 2 separate licenses for each one, can we forward data to both of them from one Heavy Forwarder? what license we should use on the HF?

Labels (1)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

You can copy same events to two or more indexer clusters just adding needed output target groups to outputs.conf. There are examples on documentation how this can done. https://docs.splunk.com/Documentation/Forwarder/8.0.5/Forwarder/Configureforwardingwithoutputs.conf  Configure data cloning on a universal forwarder with outputs.conf

 

Basically it's up to you which license server you want to use with those HFs as HFs don't use your license's capacity, just those features.

r. Ismo

jg91
Path Finder

so there is no restriction to use the same license for the HF and All Indexers (in both clusters) and simply I can use just one of those license masters, is it right?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

basically that way if/when those both clusters are use the same license from the same LM! Another restrictions (at least has had earlier) is that all members must use the same Pass4SymmKey under general stanza on server.conf.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...