Admin Manual

 


How Splunk Works

Enable cloning

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

Enable cloning

With cloning enabled, a Splunk forwarder sends its data to two or more other Splunk instances.


Configure cloning in outputs.conf on the forwarding server. Set up a target group of receiving servers to which the forwarder sends all its data.


On the forwarding server, add the following to $SPLUNK_HOME/etc/bundles/local/outputs.conf:


[tcpout]
heartbeatFrequency=10
maxQueueSize=10000
[tcpout:indexer1]
server=10.1.1.197:9997
[tcpout:indexer2]
server=10.1.1.200:9999

This configuration will send every event to both 10.1.1.197:9997 and 10.1.1.200:9999. Make sure you enable receiving on all the servers you are sending cloned data to.

This documentation applies to the following versions of Splunk: 3.2 , 3.2.1 , 3.2.2 , 3.2.3 , 3.2.4 , 3.2.5 , 3.2.6 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.