Getting Data In

Can a Universal Forwarder be used to forward indexed data on a search head to an indexer?

Ryan_Beck
Engager

Hello. I'm fairly new to Splunk and am working on configuring a Splunk infrastructure. If I have one search head server and one indexer server, any data that is indexed on the search head server should be forwarded to the indexer server. I see that there are Splunk documents that show to change the outputs.conf file to accomplish this.

However, instead of changing the outputs.conf file, could I install a universal forwarder on the search head server and use the universal forwarder to forward all indexed data to the indexer server?

I would appreciate any insight.

0 Karma
1 Solution

sk314
Builder

The search head is full Splunk Enterprise instance and includes ALL features including the forwarder features. You do not have to install a forwarder additionally. Use the outputs.conf settings to forward the data. It's a best practice. This helps you analyze the internal logs even if your search head is down.

For Reference: http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/Forwardsearchheaddata

View solution in original post

sk314
Builder

The search head is full Splunk Enterprise instance and includes ALL features including the forwarder features. You do not have to install a forwarder additionally. Use the outputs.conf settings to forward the data. It's a best practice. This helps you analyze the internal logs even if your search head is down.

For Reference: http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/Forwardsearchheaddata

Ryan_Beck
Engager

Ok I see, that makes sense and clarifies things. Thank you for your reply and the information that you provided!

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...