Splunk Enterprise

Forwarding events to 2 separate splunk indexers cluster from one HF

jg91
Path Finder

Hello, we Have 2 separate Splunk indexer clusters with 2 separate licenses for each one, can we forward data to both of them from one Heavy Forwarder? what license we should use on the HF?

Labels (1)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

You can copy same events to two or more indexer clusters just adding needed output target groups to outputs.conf. There are examples on documentation how this can done. https://docs.splunk.com/Documentation/Forwarder/8.0.5/Forwarder/Configureforwardingwithoutputs.conf  Configure data cloning on a universal forwarder with outputs.conf

 

Basically it's up to you which license server you want to use with those HFs as HFs don't use your license's capacity, just those features.

r. Ismo

jg91
Path Finder

so there is no restriction to use the same license for the HF and All Indexers (in both clusters) and simply I can use just one of those license masters, is it right?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

basically that way if/when those both clusters are use the same license from the same LM! Another restrictions (at least has had earlier) is that all members must use the same Pass4SymmKey under general stanza on server.conf.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...