<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DB Connect: Heavy Forwarder Issue in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/DB-Connect-Heavy-Forwarder-Issue/m-p/706335#M28903</link>
    <description>&lt;P&gt;That means exactly what it says - you have some searches defined (most probably because you distribute the same apps to several different kinds of splunk components) which normally should run as scheduled searches but will not because you're using a forwarder license.&lt;/P&gt;</description>
    <pubDate>Mon, 09 Dec 2024 12:56:35 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2024-12-09T12:56:35Z</dc:date>
    <item>
      <title>DB Connect: Heavy Forwarder Issue</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/DB-Connect-Heavy-Forwarder-Issue/m-p/706331#M28901</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a Heavy Forwarder, and it was configured just to forward not index:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[indexAndForward]
index = false&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I tried to install the DB Connect App on that HF but we faced the below ERROR:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DB Connect.png" style="width: 666px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33750iDB5DAB2AF21791CD/image-dimensions/666x176?v=v2" width="666" height="176" role="button" title="DB Connect.png" alt="DB Connect.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any Ideas?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2024 15:17:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/DB-Connect-Heavy-Forwarder-Issue/m-p/706331#M28901</guid>
      <dc:creator>AliMaher</dc:creator>
      <dc:date>2024-12-09T15:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect: Heavy Forwarder Issue</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/DB-Connect-Heavy-Forwarder-Issue/m-p/706333#M28902</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/268583"&gt;@AliMaher&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;which kind of license did you have on your HF?&lt;/P&gt;&lt;P&gt;to use DB-Connect, also without local indexing, you cannot use the Forwarder License, but you must configure the HF as a license client, connecting it to the License Master.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2024 12:54:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/DB-Connect-Heavy-Forwarder-Issue/m-p/706333#M28902</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-12-09T12:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect: Heavy Forwarder Issue</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/DB-Connect-Heavy-Forwarder-Issue/m-p/706335#M28903</link>
      <description>&lt;P&gt;That means exactly what it says - you have some searches defined (most probably because you distribute the same apps to several different kinds of splunk components) which normally should run as scheduled searches but will not because you're using a forwarder license.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2024 12:56:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/DB-Connect-Heavy-Forwarder-Issue/m-p/706335#M28903</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-12-09T12:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect: Heavy Forwarder Issue</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/DB-Connect-Heavy-Forwarder-Issue/m-p/706351#M28904</link>
      <description>&lt;P&gt;Why is that? Serious question. I've never tried to do so but it shouldn't need to index anything locally.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2024 15:11:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/DB-Connect-Heavy-Forwarder-Issue/m-p/706351#M28904</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-12-09T15:11:57Z</dc:date>
    </item>
  </channel>
</rss>

