A method of data distribution where one Splunk Enterprise instance routes and forwards data to one or more receiving Splunk Enterprise instances based on the data content. For example, in a situation where one forwarder routes data to two indexers, the forwarder matches conditions based on patterns in the data to selectively send some data to one of the receivers and the rest of the data to the other receiver.

You can use data routing to send event data to specific queues, indexes, or third-party systems.

You can also use data routing in conjunction with cloning and load balancing.

