<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Heavy Forwarders in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Heavy-Forwarders/m-p/220436#M23773</link>
    <description>&lt;P&gt;How is your data being forwarded in? Syslog (non universal forwarder) or Universal Forwarder based?&lt;/P&gt;</description>
    <pubDate>Fri, 22 Apr 2016 14:08:47 GMT</pubDate>
    <dc:creator>ncrisler</dc:creator>
    <dc:date>2016-04-22T14:08:47Z</dc:date>
    <item>
      <title>Heavy Forwarders</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Heavy-Forwarders/m-p/220435#M23772</link>
      <description>&lt;P&gt;Quick question about HF.&lt;/P&gt;

&lt;P&gt;Do you necessarily need two separated Splunk instances for Heavy Forwarding data? (One for receiving and one for forwarding).&lt;BR /&gt;
If not, how can you do this without tripping up with the "Forwarding to indexer group default-autolb-group blocked for 100 seconds" issue?&lt;/P&gt;

&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2016 13:08:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Heavy-Forwarders/m-p/220435#M23772</guid>
      <dc:creator>Yaichael</dc:creator>
      <dc:date>2016-04-22T13:08:59Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarders</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Heavy-Forwarders/m-p/220436#M23773</link>
      <description>&lt;P&gt;How is your data being forwarded in? Syslog (non universal forwarder) or Universal Forwarder based?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2016 14:08:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Heavy-Forwarders/m-p/220436#M23773</guid>
      <dc:creator>ncrisler</dc:creator>
      <dc:date>2016-04-22T14:08:47Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarders</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Heavy-Forwarders/m-p/220437#M23774</link>
      <description>&lt;P&gt;Typically you have one of the following:&lt;/P&gt;

&lt;P&gt;universal forwarder forwarding its data to a single indexer or group&lt;BR /&gt;
universal forwarder forwarding it data to a group of heavy forwarders to be load-balanced across multiple indexers (this is most &lt;BR /&gt;
or&lt;BR /&gt;
syslog type input being forwarded to universal forwarder to heavy forwarder(s) to indexers&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2016 14:13:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Heavy-Forwarders/m-p/220437#M23774</guid>
      <dc:creator>ncrisler</dc:creator>
      <dc:date>2016-04-22T14:13:02Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarders</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Heavy-Forwarders/m-p/220438#M23775</link>
      <description>&lt;P&gt;Hi Yaichael,&lt;/P&gt;

&lt;P&gt;Maybe this can help:&lt;/P&gt;

&lt;P&gt;To receive data from a syslog server for example you can send data directly to a Splunk Server (Splunk Indexer if you have a distributed deployment or Splunk Enterprise for single server deployment). &lt;BR /&gt;
You can also deploy Universal Forwarders to receive local data in some servers. I would suggest you install a Universal Forwarder in one of those cases:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;You want to index local log file from a server that is not the Splunk Server&lt;/LI&gt;
&lt;LI&gt;If you have a remote location and want to receive all the logs from that location in a local server and them forward this data to you Splunk Server(s)&lt;/LI&gt;
&lt;LI&gt;If you have a distributed deployment it's always better to receive data on Universal Forwarders that can auto load balance data across all your indexers&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;A Heavy Forwarder is a Splunk Server full installation that only collects data and forward that data to your splunk server or indexers. It's not very common to have heavy forwarders just in some cases, in most of the cases you can deploy a Universal Forwarder. But for some cases you must install a heavy forwarder, for example to use the app of Checkpoint LEA, of make some index time transformations.&lt;/P&gt;

&lt;P&gt;Hope this can helps you&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2016 18:49:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Heavy-Forwarders/m-p/220438#M23775</guid>
      <dc:creator>gfreitas</dc:creator>
      <dc:date>2016-04-22T18:49:04Z</dc:date>
    </item>
  </channel>
</rss>

