Getting Data In

Why do we require splunk forwarder as we can have splunk installed and splunkd service can capture everything ???

rashokciet
New Member

In all our servers splunk 6.1.5 has been installed and splunkd service is capturing all the required data.So what is the use of splunk forwarder ??Is there any benefit having splunk forwarder rather than running splunkd and where do we use it???

Tags (1)
0 Karma
1 Solution

jeffland
SplunkTrust
SplunkTrust

A "splunkd" running somewhere that sends its data to another machine essentially is a fowarder; a forwarder is not something "extra": http://docs.splunk.com/Splexicon:Forwarder

Comparing the different variants of a forwarder, the benefit of a heavy forwarder as opposed to a light/universal forwarder is that it can filter your data on event level before it hits your index, so it can save you some indexing volume (and network bandwith/processing power on the indexer).

You could also make use of intermediate forwarders: http://docs.splunk.com/Documentation/Splunk/6.2.2/Forwarding/Forwarderdeploymenttopologies#Intermedi...

View solution in original post

mikelanghorst
Motivator

"Splunk Forwarder" is typically referring to the lighter weight install of the Splunk Universal Forwarder or UF. It has a smaller disk footprint with some functionality stripped out, and smaller memory usage. Typically if you're only reading files or running scripted inputs, such as Splunk_TA_nix, the UF is all that's needed. However as jeffland mentions there are some occasions that the full install or heavy forwarder is desired. Being able to filter unneeded data before hitting the wire, or acting as a collection node between data centers being 2 of those reasons.

rashokciet
New Member

Splunkd can handle search request and splunk forwarder cannot handle search request - Is that correct??
The searching is done by splunk web so both should handle search request ??? I am confused.

Your help was and will be appreciated.

0 Karma

jeffland
SplunkTrust
SplunkTrust

That's kinda in the right direction. I would encourage you to learn about splunk architecture to understand the different system parts and how they work together: http://www.splunk.com/view/SP-CAAABF9 and http://docs.splunk.com/Documentation/Splunk/6.2.2/Deploy/Distributedoverview

0 Karma

jeffland
SplunkTrust
SplunkTrust

A "splunkd" running somewhere that sends its data to another machine essentially is a fowarder; a forwarder is not something "extra": http://docs.splunk.com/Splexicon:Forwarder

Comparing the different variants of a forwarder, the benefit of a heavy forwarder as opposed to a light/universal forwarder is that it can filter your data on event level before it hits your index, so it can save you some indexing volume (and network bandwith/processing power on the indexer).

You could also make use of intermediate forwarders: http://docs.splunk.com/Documentation/Splunk/6.2.2/Forwarding/Forwarderdeploymenttopologies#Intermedi...

rashokciet
New Member

Thanks jeffland

0 Karma

gyslainlatsa
Motivator

hi rashokciet,

i don't know if this resolve your problem but i know that:
splunk operates together with the splunkd server and splunkweb interface. the server works in the background while the interface allows us to visualize the data.
splunk forwarder is important in a distributed environment, in this environment we need to send data from our machine to other machines. splunk forwrder is very important in case you frequently send the output data.

please forgive my english

rashokciet
New Member

Thanks gyslainlatsa

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...