HI @ucorral, if you have an intermediate Heavy Forwarder, you could create a fork on it and send some logs both to your on-premise and Splunk Cloud. You can do this following the instructions at https://docs.splunk.com/Documentation/Splunk/9.1.0/Forwarding/Routeandfilterdatad#Filter_and_route_event_data_to_target_groups remember that the outputs.conf configurations for your Splunk Cloud instance are downloaded by Splunk Cloud in a dedicated App. If you haven't an Heavy Forwarder, you have to install the above fork in all your Forwarders. Ciao. Giuseppe
... View more