if i send all syslog data to one splunk enterprise instance to be indexed and then it is forwarded onto another splunk enterprise instance.
Is the second splunk instance smart enough to know this data has already been indexed and doesnt count towards your daily license quota?
Thanks
short answer, yes
there are many words on this topic here so here are couple of links that elaborate on the topic and shows ways around it.
https://answers.splunk.com/answers/103186/does-data-indexed-and-forwarded-from-a-heavy-forwarder-cou...
https://answers.splunk.com/answers/230480/indexing-data-and-forward-to-another-indexer.html
https://answers.splunk.com/answers/70017/heavy-forwarder-costs-and-licenses.html
hope it helps
It will absolutely hit your index volume a second time, assuming you are forwarding via syslog or splunk output.
You can make use of summary indexing or collect
to search and index the results of said search, which won't hit your license cost again, but you don't want to do this for large amounts of data as a means to have two copies of all your data.