Hello,
I would like to know if that possible to configure on a single splunk fowarder, 2 distincts inputs and outputs.
In a concrete way, i would to receive the inputs logs coming from :
The only configuration i see, is centralizing the logs in a single point from the inputs, and send them to the outputs.
I want 2 distincts flow is it possible ?
It should look like this
Thanks !
You sure can! You will need to use TCP_ROUTING in your inputs.
So it might go something like this:
[outputs.conf]
[tcpout:UDP10001]
server=server1:9997
[tcpout:UDP10002]
server=server2:9997
[inputs.conf]
[udp://10001]
_TCP_ROUTING = UDP10001
[udp://10002]
_TCP_ROUTING = UDP10002