Getting Data In

what is Index , search and Heavy forwarder and how they are related each other please i need help

sujeet11dec
New Member

I have 3 Ubuntu machine , but i dont know what index , search and heavy forwarder and how they are related to each other .

Please help me i am vary new into IT Security and i got splunk as an first project

Tags (2)
0 Karma

n00badmin
Communicator

Have you installed Splunk Enterprise on the machines?

0 Karma

n00badmin
Communicator

You simply need to install Splunk Enterprise on 3 linux machines and configure one to forward and one to be a search only.

http://docs.splunk.com/Documentation/Splunk/latest/Installation/Whatsinthismanual

0 Karma

sujeet11dec
New Member

Hi n00badmin

Please i need your small help here what need to be a machine work as index , search or heavy Forwarder as per configration wise

sujeet

0 Karma

n00badmin
Communicator

First you should do some reading. Splunk documentation is some of the best

http://docs.splunk.com/Documentation/Splunk

A heavy forwarder is a full install of splunk that forwards data to an indexer.

The indexer indexes the data into indexes searchable from the searchhead.

START HERE : http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Distributedoverview

0 Karma

sujeet11dec
New Member

Please i need brief answer

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...