I need to Forward All Windows Security/Application/system logs to 2 Separate Splunk instances with different Index names. so
Security log ------- Index1 on serverA , Index2 on ServerB
in my Input.cof on my UF do i use Index=index1,Index2
Then in Output of HF send to Index_servers= ServerA/ServerB
I need to make sure ServerB does not get hit with Index1