Getting Data In

Can I have a forwarder and indexer on the same machine just for experiment?

normangoh
Explorer

Hi Guys,

I am new to Splunk and I have play around the Splunk Enterprise for a few days. I managed to add data from my local network to monitor how Splunk works. However, when I tried to set up a forwarder sending data to my local index on the same machine it always end up having the forwarder blocked.

I understand that a single Splunk instance cannot be used as a forwarder and a indexer at the same time, but is there any other way that I could play around with a forwarder and indexer on the same machine?

Tags (2)
0 Karma
1 Solution

MuS
Legend

Hi normangoh,

Yes, you can do so. There must be something else wrong, like did you enable the receiving port on the indexer? Check out the docs on this topic http://docs.splunk.com/Documentation/Splunk/6.2.3/Forwarding/Enableareceiver it also includes some troubleshooting.

cheers, MuS

View solution in original post

frmaasdam
Path Finder

You can install several splunk instances in different directories on the same server.

For example /opt/splunk1/ as indexer1 and /opt/splunk2/ as indexer2
Use different port numbers for webinterface, replication etc etc
You can now start each splunk instance separately.
I have used this to test multi indexer cluster environment on one server.

0 Karma

frmaasdam
Path Finder

Yes you can. I have a Master Deployment Forwarder 2 indexers and a Search head instance. In total 6 instances rrunning on 1 server.

0 Karma

kushagra9120
Explorer

Ho w did you install 2 indexers on same machine

0 Karma

MuS
Legend

Hi normangoh,

Yes, you can do so. There must be something else wrong, like did you enable the receiving port on the indexer? Check out the docs on this topic http://docs.splunk.com/Documentation/Splunk/6.2.3/Forwarding/Enableareceiver it also includes some troubleshooting.

cheers, MuS

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...