Getting Data In

What are the capabilities of the Splunk Forwarder license?

FritzWittwer_ol
Contributor

We are running heavy forwarders to accept events from a number of universal forwarders, do some transforms and filtering with props and transforms, and then send them to our indexers.

We'd like to use the forwarder license on them, so we don't have to enable a connection to our license master. What capabilities are enabled with this license? Or more specific, are the functions of the parsing, merging and typing pipelines, according to HowIndexingWorks, available with the forwarding license?

0 Karma

vishaltaneja070
Motivator

Hello @FritzWittwer,

Forwarder license is already included in every splunk package which only allows data forwarding nothing else not even parsing.
The Forwarder license allows forwarding of unlimited data. Unlike a Free license, it enables authentication.

The Forwarder license is available only for instances that simply forward data. It is not valid for use on instances that also perform additional functions, such as indexing.

Forwarder licenses are included with Splunk. You do not need to purchase them separately.

There are several types of forwarders:

The universal forwarder has the Forwarder license applied automatically.
The light forwarder uses the Forwarder license, but you must manually enable it by changing to the Forwarder license group.
The heavy forwarder must also be manually converted to the Forwarder license group. If the heavy forwarder will also be performing indexing, the forwarder must instead have access to an Enterprise license.

Please see the below link:
https://docs.splunk.com/Documentation/Splunk/7.2.3/Admin/TypesofSplunklicenses

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...