Getting Data In

Question on heavy forwarder

splunker12er
Motivator

Heavy forwarders can index and forward the data to Splunk indexers. In this case do we need any local configurations (props,transforms,etc) at indexers side., since we need to set all the local configurations at heavy forwarder itself. What is the format of the indexed data from the heavy forwarder to indexer ?

Does the format of the indexed data in heavy forwarder & indexer are similar ?

Can i point a universal forwarder to Splunk heavy forwarder ?

Tags (1)
0 Karma

lguinn2
Legend

The format between the heavy forwarder and indexer is "cooked" - which means the data after parsing, along with the metadata. All the parsing configurations need to be set on the heavy forwarder (props.conf, transforms.conf). However, some settings may need to be on the indexer or search head. While you can figure out the differences, I think it is just easier to have a duplicate of the props.conf and transforms.conf in both places - Splunk will ignore any settings it doesn't need.

If you are keeping a local index on the heavy forwarders, then it isn't really just a forwarder is it! Regardless of where you index the data, the format will be the same. BTW, if your heavy forward is set to "index and forward", it will need a Splunk license.

Yes, you can point a universal forwarder to a heavy forwarder. It works great. Just be sure to set up the receiving port on the heavy forwarder, and well as outputs.conf on the universal forwarder.

Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...