Getting Data In

Forward Data

Kendo213
Communicator

I need to index data from an appliance we have, however in the appliance you can only specify one syslog server. How can I index the data on our central instance and then forward the data on to a separate heavy forwarder?

We basically have two separate Splunk instances so I need to figure out how to get the data to both of them.

Tags (1)
0 Karma

Ayn
Legend

You can route specific events to other Splunk instances, and/or index them locally on the Splunk instances you're routing the events from. See more here: http://docs.splunk.com/Documentation/Splunk/6.0/Forwarding/Routeandfilterdatad

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...