<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Question for splunk architecture in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Question-for-splunk-architecture/m-p/539841#M18538</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have plan to install Splunk Enterprise SIEM in the cyber security operation center, and universal forwarder will be installed on each workstation in order to transmit windows event log.&lt;/P&gt;&lt;P&gt;From what I studied at the splunk site, it seems that I can design Architecture 1 or 2 as shown in the picture below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="splunk picture.JPG" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12934i29A3665B725DF143/image-size/medium?v=v2&amp;amp;px=400" role="button" title="splunk picture.JPG" alt="splunk picture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I would like to know the pros and cons of using a heavy forwarder because I need to purchase an additional server to install Heavy Forwarder.&lt;/P&gt;&lt;P&gt;Also, I want to get technical support for purchase from korea engineer.&lt;/P&gt;&lt;P&gt;Could you please give me email address for technical support? I could not find email address about korea engineer in splunk website.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;</description>
    <pubDate>Sun, 14 Feb 2021 16:31:02 GMT</pubDate>
    <dc:creator>kevinsteeee</dc:creator>
    <dc:date>2021-02-14T16:31:02Z</dc:date>
    <item>
      <title>Question for splunk architecture</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Question-for-splunk-architecture/m-p/539841#M18538</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have plan to install Splunk Enterprise SIEM in the cyber security operation center, and universal forwarder will be installed on each workstation in order to transmit windows event log.&lt;/P&gt;&lt;P&gt;From what I studied at the splunk site, it seems that I can design Architecture 1 or 2 as shown in the picture below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="splunk picture.JPG" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12934i29A3665B725DF143/image-size/medium?v=v2&amp;amp;px=400" role="button" title="splunk picture.JPG" alt="splunk picture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I would like to know the pros and cons of using a heavy forwarder because I need to purchase an additional server to install Heavy Forwarder.&lt;/P&gt;&lt;P&gt;Also, I want to get technical support for purchase from korea engineer.&lt;/P&gt;&lt;P&gt;Could you please give me email address for technical support? I could not find email address about korea engineer in splunk website.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;</description>
      <pubDate>Sun, 14 Feb 2021 16:31:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Question-for-splunk-architecture/m-p/539841#M18538</guid>
      <dc:creator>kevinsteeee</dc:creator>
      <dc:date>2021-02-14T16:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: Question for splunk architecture</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Question-for-splunk-architecture/m-p/539848#M18540</link>
      <description>&lt;P&gt;Architecture 1 rarely makes sense.&amp;nbsp; The heavy forwarder is a bottleneck, a single point of failure, adds traffic to the network, creates management and troubleshooting complexity, and can lead to data that is not well-balanced among indexers.&amp;nbsp; Architecture 2 avoids all of those problems.&lt;/P&gt;</description>
      <pubDate>Sun, 14 Feb 2021 18:47:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Question-for-splunk-architecture/m-p/539848#M18540</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-02-14T18:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: Question for splunk architecture</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Question-for-splunk-architecture/m-p/539871#M18544</link>
      <description>&lt;P&gt;Version 1 is ok if you need to do some with data before data get to the index, or for some reason client do not have directly connect with index server.&lt;/P&gt;&lt;P&gt;We do use version 1 since we have multiple customers that we store in different indexer.&amp;nbsp; Eks customer x sends data to syslog, the heavy forwarder change index name from index=syslog to index=x-syslog, and for customer y to index=y-syslog.&amp;nbsp; We know then that the data are separated within out Splunk solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Version 2 need less server and are ok if you can write directly to the indexer and do not need to change/trim data before it enters the index.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 07:17:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Question-for-splunk-architecture/m-p/539871#M18544</guid>
      <dc:creator>jotne</dc:creator>
      <dc:date>2021-02-15T07:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: Question for splunk architecture</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Question-for-splunk-architecture/m-p/539872#M18545</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/58370"&gt;@kevinsteeee&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;,.&amp;nbsp;the second architecture is better than the first for the reasons he described.&lt;/P&gt;&lt;P&gt;There's only one situation where the first is better: when you don't want to open all the routes between servers with UF and Indexer e.g. for security reasons: in this case the solution is the first but using two Heavy Forwarders to avoid a bottleneck and a Single Point of Failure.&lt;/P&gt;&lt;P&gt;If you don't have this requirement, use your second!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 07:19:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Question-for-splunk-architecture/m-p/539872#M18545</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-02-15T07:19:40Z</dc:date>
    </item>
    <item>
      <title>Re: Question for splunk architecture</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Question-for-splunk-architecture/m-p/541137#M18576</link>
      <description>&lt;P&gt;&lt;STRONG&gt;single point of failure,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Not directly true.&amp;nbsp; There are noe problem having more than one HF.&lt;/P&gt;&lt;P&gt;We do use HF to overcome security issue and filtering before data reach index server.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2021 08:47:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Question-for-splunk-architecture/m-p/541137#M18576</guid>
      <dc:creator>jotne</dc:creator>
      <dc:date>2021-02-24T08:47:35Z</dc:date>
    </item>
  </channel>
</rss>

