Getting Data In

Can anyone help me how to configure heavy forwarder?

raghu0479
New Member

I installed the Splunk enterprise on Linux, I used universal forwarder and I could get my logs using it on my Splunk instance, now I want to parse my logs using a heavy forwarder, can anyone help me how to Configure it?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi raghu0479,
I think that you need an Heavy Forwarder because you have different needs than a Universal Forwarder.
Anyway, you have to:

  • install a normal full Splunk Enterprise,
  • go in [Settings -- Forwarding and Receiving]
  • Configure Forwarding -- Default: Store a local copy of forwarded events? NO
  • Configure Forwarding -- Forward Data -- New Forwarding Host: insert hostname:port or IP:port
  • repeat the last configuration for all your indexers
  • system will request a splunk restart

Bye.
Giuseppe

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If the universal forwarder works, why replace it with a heavy forwarder? Performance is better with the UF.

---
If this reply helps you, Karma would be appreciated.
0 Karma

raghu0479
New Member

Hi richgalloway, I have a requirement to use the heavy forwarder, so if you have an idea of how to filter the logs using a heavy forwarder, Please share ur thoughts.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Have you explained to the person who gave you this requirement that a UF performs better than an HF?

You need to give us more to work with. What filtering do you need to do? What logs are you filtering?
You may be better off filtering with syslog-ng or the indexer rather than a heavy forwarder.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...