<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure Splunk Heavy Forwarder and Splunk Searchhead on the same machine? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-Heavy-Forwarder-and-Splunk-Searchhead-on/m-p/407613#M72269</link>
    <description>&lt;P&gt;Hi sarvesh_11,&lt;/P&gt;

&lt;P&gt;I can see Two ways:&lt;BR /&gt;
1 - transform your UF in HF&lt;BR /&gt;
2 - install splunk enterprise on the "SH" server, then configure inputs. conf, outputs.conf and TA if necessary as you should do it on the HF.&lt;/P&gt;

&lt;P&gt;A single instance can have multiple roles.&lt;/P&gt;

&lt;P&gt;Cheers.&lt;/P&gt;

&lt;P&gt;Olivier.&lt;/P&gt;</description>
    <pubDate>Fri, 26 Jul 2019 06:57:48 GMT</pubDate>
    <dc:creator>o_calmels</dc:creator>
    <dc:date>2019-07-26T06:57:48Z</dc:date>
    <item>
      <title>How to configure Splunk Heavy Forwarder and Splunk Searchhead on the same machine?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-Heavy-Forwarder-and-Splunk-Searchhead-on/m-p/407612#M72268</link>
      <description>&lt;P&gt;Hi @gcusello (tagging u because i have seen many of your answers in this context &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; ) ,&lt;BR /&gt;
Is it possible to configure Splunk Heavy Forwarder and Search head on the same machine?&lt;BR /&gt;
As our indexer is on Splunk Cloud, for the data formatting, to work on props.conf we need a heavy forwarder in between UF and Indexer. Also, i am restricted for the count of machine i can engage.&lt;BR /&gt;
What i am left with is, to configure HF and SH on same machine.&lt;/P&gt;

&lt;P&gt;TIA&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2019 06:46:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-Heavy-Forwarder-and-Splunk-Searchhead-on/m-p/407612#M72268</guid>
      <dc:creator>sarvesh_11</dc:creator>
      <dc:date>2019-07-26T06:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure Splunk Heavy Forwarder and Splunk Searchhead on the same machine?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-Heavy-Forwarder-and-Splunk-Searchhead-on/m-p/407613#M72269</link>
      <description>&lt;P&gt;Hi sarvesh_11,&lt;/P&gt;

&lt;P&gt;I can see Two ways:&lt;BR /&gt;
1 - transform your UF in HF&lt;BR /&gt;
2 - install splunk enterprise on the "SH" server, then configure inputs. conf, outputs.conf and TA if necessary as you should do it on the HF.&lt;/P&gt;

&lt;P&gt;A single instance can have multiple roles.&lt;/P&gt;

&lt;P&gt;Cheers.&lt;/P&gt;

&lt;P&gt;Olivier.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2019 06:57:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-Heavy-Forwarder-and-Splunk-Searchhead-on/m-p/407613#M72269</guid>
      <dc:creator>o_calmels</dc:creator>
      <dc:date>2019-07-26T06:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure Splunk Heavy Forwarder and Splunk Searchhead on the same machine?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-Heavy-Forwarder-and-Splunk-Searchhead-on/m-p/407614#M72270</link>
      <description>&lt;P&gt;Hi sarvesh_11,&lt;BR /&gt;
Heavy Forwarder is a full Splunk installation where all logs are redirected to Indexers; it's also possible to locally index data but this shouldn't be your requirement!&lt;BR /&gt;
Search Head is a full Splunk installation used for User Interface and usually, when you configure a SH, it's a good practice to send SH's logs to the indexers, in other words to use it as an HF.&lt;BR /&gt;
So you can use a server for both your roles.&lt;/P&gt;

&lt;P&gt;The question is: why to do this? &lt;BR /&gt;
In Splunk Cloud you have both Indexers and Search Heads, not only Indexers.&lt;BR /&gt;
The advantage to have Splunk Cloud is that all the Splunk infrastructure is accessible in cloud.&lt;BR /&gt;
In addition, in Splunk Cloud you access only Search Heads, you cannot access Indexers! so there's no sense to have a local SH.&lt;/P&gt;

&lt;P&gt;Anyway, if you want to do this, remember to correctly dimention your server for both the roles (in terms of CPUs and RAM).&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2019 07:29:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Splunk-Heavy-Forwarder-and-Splunk-Searchhead-on/m-p/407614#M72270</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-07-26T07:29:32Z</dc:date>
    </item>
  </channel>
</rss>

