Quantcast
Channel: Questions in topic: "universal-forwarder"
Viewing all articles
Browse latest Browse all 1551

How do I configure the outputs.conf file to forward data into two separate instances of Splunk?

$
0
0
Hello Splunk user community, i have Linux VMS that are already reporting into a Splunk enterprise instance using a universal forwarder (UF). I recently set up a Splunk POC instance and would like to leverage the existing UFs to fork that data into my Splunk POC simultaneously. To be specific, i'm implementing the collectd daemon for the 1st time to support a Splunk application. It attempts to deploy the UF and if one is already present, it ignores the UF but does install the collectd. i know of the outputs.conf and using stanzas, but I just need the syntax to make this happen. This is what i currently have and i need to add to it... [t-splunk@lgtisplunk1 ~]$ cat /apps/splunk/etc/system/local/outputs.conf [tcpout] defaultGroup = default-autolb-group [tcpout:default-autolb-group] server = lgtisplunk1.calpers.ca.gov:9997 [tcpout-server://lgtisplunk1.calpers.ca.gov:9997] thank you, david

Viewing all articles
Browse latest Browse all 1551

Trending Articles