Heavy forwarders are currently configured to send some palo alto logs to one server1 . Can you please forward a copy of that same traffic to different serve2r(indexer), UDP 514? Current forwarding to server1 must remain in place.
where can i check the outputs.conf file for in any specified apps or sytem local .
I asked them and they are saying logs are being sent from the palo alto firewall to HF . So how can i forward a copy of that to another (server)indexer
I think this may help you:
https://answers.splunk.com/answers/92257/can-single-forwarder-forward-data-to-two-different-indexers...