1) A -> B
This will be your normal splunk configuration that will forward data from server A to splunk server B
2) B -> C
To Send data from splunk server B to server C do the following;
Create a shell script with splunk CLI search redirecting data to a data file.
SCP the file to server C
Example of steps in the shell will be;
$SPLUNK_HOME/bin/splunk search 'index=* search string' -earliest_time='-1d' -latest_time='now' > datafile
scp ./datafile user@server:/path/
Let me know if that works for you.
Regards
Sinclair
... View more