Getting Data In

Does data indexed and forwarded from a heavy forwarder count against the Splunk data license?

mookiie2005
Communicator

We have a Heavy forwarder load balancing data feeds from a TCP/UDP feeds to the two indexers we are using. My question is does the data indexed and then forwarded from the heavy forwarder to either indexer count against the Splunk license? This would basically charge the customer twice to index the same data. Once at the heavy forwarder and than again at the indexers. Would this change if the IndexandForward attribute was set to false?

1 Solution

kristian_kolb
Ultra Champion

Yes. A heavy forwarder is essentially an indexer, where indexing has been turned off. Turning it back on, like with indexAndForward, will require a license in order to make the events searchable on that machine.

As for charging for indexing the same data twice, that used to be one of the ways to make a Splunk installation more HA/DR-like, and I believe that you could get some sort of license discount for those types of scenarios. Since version 5, there is index replication to cater for that need (which lets your indexers make copies already indexed data at no extra cost, apart from the extra storage required).

Setting indexAndForward=false would let your Heavy Forwarder act as just that.

Hope this clarifies things a bit,

K

View solution in original post

kristian_kolb
Ultra Champion

Yes. A heavy forwarder is essentially an indexer, where indexing has been turned off. Turning it back on, like with indexAndForward, will require a license in order to make the events searchable on that machine.

As for charging for indexing the same data twice, that used to be one of the ways to make a Splunk installation more HA/DR-like, and I believe that you could get some sort of license discount for those types of scenarios. Since version 5, there is index replication to cater for that need (which lets your indexers make copies already indexed data at no extra cost, apart from the extra storage required).

Setting indexAndForward=false would let your Heavy Forwarder act as just that.

Hope this clarifies things a bit,

K

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...