I have installed splunk universal forwarder on ec2 instances which forward data to splunk heavy forwarder. In order to route the date to Splunk on premise, I need to configure splunk heavy forwarder. I have configured heavy forwarder to route date to splunk cloud. How to configure the same to forward the data to on-premise.
Hi
just add another target group ( like you have for Splunk cloud) for onprem in your outputs.conf.
Hi
just add another target group ( like you have for Splunk cloud) for onprem in your outputs.conf.
Thanks, that worked.