Splunk Enterprise

Forwarding events to 2 separate splunk indexers cluster from one HF

jg91
Path Finder

Hello, we Have 2 separate Splunk indexer clusters with 2 separate licenses for each one, can we forward data to both of them from one Heavy Forwarder? what license we should use on the HF?

Labels (1)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

You can copy same events to two or more indexer clusters just adding needed output target groups to outputs.conf. There are examples on documentation how this can done. https://docs.splunk.com/Documentation/Forwarder/8.0.5/Forwarder/Configureforwardingwithoutputs.conf  Configure data cloning on a universal forwarder with outputs.conf

 

Basically it's up to you which license server you want to use with those HFs as HFs don't use your license's capacity, just those features.

r. Ismo

jg91
Path Finder

so there is no restriction to use the same license for the HF and All Indexers (in both clusters) and simply I can use just one of those license masters, is it right?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

basically that way if/when those both clusters are use the same license from the same LM! Another restrictions (at least has had earlier) is that all members must use the same Pass4SymmKey under general stanza on server.conf.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...