Deployment Architecture

How to consider my server acts as a Heavy Forwarder

anandhalagarasa
Path Finder

Hi Team,

We have Splunk Cloud deployed in our environment and we have built an heavy forwarder server. And here we have placed some props and transforms for filtration but actually when i check the data in Splunk Cloud the Regex is not getting applied and hence forth the data seems to be still the improper format so i want to know how to check whether my server is acting as an heavy forwarder or not.

And also how to check whether it is doing a filtering option before indexing in Splunk Cloud.

Kindly let me know on this.

Tags (1)
0 Karma

adonio
Ultra Champion

have always a small instance of splunk that you can fully control - all in 1
on-board the data and tweak your props and transforms accordingly
verify you see the data as you wish, then package your configurations neatly and move them to your Heavy Forwarder

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...