data cloning

noun

A data distribution setup in which a Splunk forwarder sends copies of its events to two or more receiving indexers. Data cloning can be used in conjunction with load balancing and data routing. Data cloning usually results in similar, but not necessarily exact, copies of data on the receiving indexers. Data cloning can be enabled on the forwarder through outputs.conf.

For more information

In the Distributed Deployment Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time