Splunk Search

Single Source of Data, Multiple Splunk Instances?

gmark
Explorer

We have a single data simulator sending records to a socket, and a Splunk instance on a different server using that data. Can we have additional Splunk instances using that same data?

Tags (1)

gmark
Explorer

I have multiple Splunk instances, but not in this case. Here, I'm only thinking of piggy-backing this particular instance on the data input used by one of the others I have running.

0 Karma

jensonthottian
Contributor

Yes you can.
Use the forwarder outputs.conf to send data to additional Splunk Indexers below to different environments.

[tcpout:1st Indexername]

disabled = false

server = IPAdressof1stindexer:port

[tcpout:2ndIndexeer]

disabled = false

server =IPof2ndIndexer:portNo


Do you have multiple Splunk environments??

Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...