Getting Data In

Can a Universal Forwarder be used to forward indexed data on a search head to an indexer?

Ryan_Beck
Engager

Hello. I'm fairly new to Splunk and am working on configuring a Splunk infrastructure. If I have one search head server and one indexer server, any data that is indexed on the search head server should be forwarded to the indexer server. I see that there are Splunk documents that show to change the outputs.conf file to accomplish this.

However, instead of changing the outputs.conf file, could I install a universal forwarder on the search head server and use the universal forwarder to forward all indexed data to the indexer server?

I would appreciate any insight.

0 Karma
1 Solution

sk314
Builder

The search head is full Splunk Enterprise instance and includes ALL features including the forwarder features. You do not have to install a forwarder additionally. Use the outputs.conf settings to forward the data. It's a best practice. This helps you analyze the internal logs even if your search head is down.

For Reference: http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/Forwardsearchheaddata

View solution in original post

sk314
Builder

The search head is full Splunk Enterprise instance and includes ALL features including the forwarder features. You do not have to install a forwarder additionally. Use the outputs.conf settings to forward the data. It's a best practice. This helps you analyze the internal logs even if your search head is down.

For Reference: http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/Forwardsearchheaddata

Ryan_Beck
Engager

Ok I see, that makes sense and clarifies things. Thank you for your reply and the information that you provided!

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...