I had tried to set the configuration from all the question that have been asked at the Splunk answers, in my experiments by using props and transforms it's only reroute the data into another index. So it's like replacing the existing index that we already set up in inputs.conf.
Here's my example :
inputs.conf:
[script://./bin/top.sh]
interval = 60
sourcetype = top
source = top
index = os
disabled = 0
Props.conf
[top]
TRANSFORMS-duplicate1 = replicate1, replicate2
Transforms.conf
[replicate1]
REGEX = .
DEST_KEY = _MetaData:Index
FORMAT = os
[replicate2]
REGEX = .
DEST_KEY = _MetaData:Index
FORMAT = test2
So what i want to do here is to replicate the exact same data into two different indexes without consuming license, any idea?
... View more