Splunk Enterprise

difference between heavy forwarder and universal forwarder

sonusngh68
New Member

Can somebody briefly explain difference between Universal Forwarder and Heavy Forwarder?

Also is it possible that we can use Heavy Forwarder to forward, parse and index data without Indexer?

Tags (1)
0 Karma

deepashri_123
Motivator

Heu sonushgh68,

You can refer this doc and also this accepted answer in splunk for your reference:
http://docs.splunk.com/Documentation/SplunkCloud/7.0.0/Forwarding/Typesofforwarders
https://answers.splunk.com/answers/317035/indexer-and-heavy-forwarder-in-once.html

Let me know if this helps!!

0 Karma

tiagofbmm
Influencer

Hi

A Universal Forwarder has no capability to parse data some metadata stamping on the events.

A Heavy Forwarder is a full Splunk Instance with all the capabilities of Splunk Enterprise. You can simultaneously use a Heavy Forwarder to send data (just like a Universal Forwarder does) and also parse and Index data.

Note one thing: when data goes through the parsing pipeline in a Heavy Forwarder, either it is indexed or it is sent already processed. On the contrary, data coming out of a Universal Forwarder goes in blocks, meaning it hasn't been "cooked" (line breaking, line merging, truncating etc).

tiagofbmm
Influencer

Please let me know if the answer was useful for you. If it was, accept it and upvote. If not, give us more input so we can help you with that

0 Karma

SamHTexas
Builder

Hello  sir, do you by any chance know how to set up Alerts for a few Heavy Forwarders we have to notify us when the rate of output / sending data decreases below a certain level like 15% of the daily total? Thank u in advance.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...