Getting Data In

I have a forwarder configured to the Forwarder license group, but why is it displayed next to "Indexer name" under Under Settings > Licensing?

saifuddin9122
Path Finder

Hello

I have a doubt regarding the information of server displayed in the Licensing [settings-->Licensing]. I have a forwarder which is configured to the Forwarder license group, but the information is displayed as INDEXER NAME. May I know the why it is displayed as an indexer, even though it is a forwarder..??
alt text

0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

Every splunk instance (except Universal Forwarders) is an indexer, license master, deployment server, search head deployer and a search head by default. When looking at local license usage, it will show as an indexer regardless of what it is because every splunk instance is indeed an indexer even when it is not used as an indexer. You're basically splitting hairs on nomenclature when there really is no issue.

To summarize, every splunk instance is an indexer (besides universal forwarders) even if the instance is forwarding the data it "indexes" to other peers.

View solution in original post

jkat54
SplunkTrust
SplunkTrust

Every splunk instance (except Universal Forwarders) is an indexer, license master, deployment server, search head deployer and a search head by default. When looking at local license usage, it will show as an indexer regardless of what it is because every splunk instance is indeed an indexer even when it is not used as an indexer. You're basically splitting hairs on nomenclature when there really is no issue.

To summarize, every splunk instance is an indexer (besides universal forwarders) even if the instance is forwarding the data it "indexes" to other peers.

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...