Hi @jsingh03, as I said, Splunk index isn't a database table, is a container for data. You can recognize if an index belongs to an indexer or to another using the splunk_server field. In addition, as I said, think that duplicating logs you pay twice the Splunk License. Maybe it could be better to have an Indexer Cluster that automatically duplicates logs and you don pay twice them. For this reason the correct approach is the one from @PickleRick : what are your business requirement? in other words, what's the process that you have in place? Ciao. Giuseppe
... View more