I installed the Splunk enterprise on Linux, I used universal forwarder and I could get my logs using it on my Splunk instance, now I want to parse my logs using a heavy forwarder, can anyone help me how to Configure it?
Hi raghu0479,
I think that you need an Heavy Forwarder because you have different needs than a Universal Forwarder.
Anyway, you have to:
Bye.
Giuseppe
If the universal forwarder works, why replace it with a heavy forwarder? Performance is better with the UF.
Hi richgalloway, I have a requirement to use the heavy forwarder, so if you have an idea of how to filter the logs using a heavy forwarder, Please share ur thoughts.
Have you explained to the person who gave you this requirement that a UF performs better than an HF?
You need to give us more to work with. What filtering do you need to do? What logs are you filtering?
You may be better off filtering with syslog-ng or the indexer rather than a heavy forwarder.