<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to stop indexing forwarded data from heavy forwarder that indexes locally in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-indexing-forwarded-data-from-heavy-forwarder-that/m-p/452933#M78449</link>
    <description>&lt;P&gt;Thanks for the citation.  That answer has since changed.&lt;BR /&gt;&lt;BR /&gt;
Information on Answers is not official and not always definitive.  See this answer: &lt;A href="https://answers.splunk.com/answers/506909/heavy-forwarder-as-indexer-and-license-usage.html"&gt;https://answers.splunk.com/answers/506909/heavy-forwarder-as-indexer-and-license-usage.html&lt;/A&gt;&lt;BR /&gt;
I'm struggling to find this mentioned in official Splunk docs.&lt;/P&gt;</description>
    <pubDate>Mon, 01 Jul 2019 18:24:44 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2019-07-01T18:24:44Z</dc:date>
    <item>
      <title>How to stop indexing forwarded data from heavy forwarder that indexes locally</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-indexing-forwarded-data-from-heavy-forwarder-that/m-p/452930#M78446</link>
      <description>&lt;P&gt;Reading from article : &lt;STRONG&gt;Does data indexed and forwarded from a heavy forwarder to indexer would charge twice?&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Any indexed forwarded events from a Heavy forwarded are NOT licensed twice.&lt;/P&gt;

&lt;P&gt;When Indexing and forwarding from a Heavy Forwarder, the licensing is only used at the Heavy Forwarder, since indexed Data sent to the Indexer, doesn't go through the Parsing queue (as well as the Aggregator and Typing queues).&lt;/P&gt;

&lt;P&gt;I have setup the following on my Heavy Forwarder:&lt;/P&gt;

&lt;P&gt;outputs.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;defaultGroup = default-autolb-group

[tcpout:default-autolb-group]
server = rdbrsdem03.ref.clp7.local:9997
indexAndForward=true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[source::tcp:9999]
BREAK_ONLY_BEFORE=^CEF\:0\|
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So on my heavy forwarder, I am sending indexed data to my indexer (rdbrsdem03), and it also filters all events that start with  &lt;CODE&gt;CEF:0|&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;When I check licensing it seems as if the events &lt;STRONG&gt;ARE&lt;/STRONG&gt; being indexed on both the Heavy Forwarder and Indexer.&lt;/P&gt;

&lt;P&gt;Can someone provide me with a search possibly using the 'summary' index that proves the events are only being index at the Heavy Forwarder, please?&lt;/P&gt;

&lt;P&gt;I have a developer license at the moment so would like to prove that events that need to be indexed at the Heavy Forwarder (due to local users in a remote site being able to search events of their local hardware events) and then not being reindexed (in effect doubling licensing costs) on the Indexer.&lt;/P&gt;

&lt;P&gt;Hope this all makes sense, please let me know if there is anything further you may need.&lt;/P&gt;

&lt;P&gt;kind regards&lt;/P&gt;

&lt;P&gt;Damindra&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 11:45:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-indexing-forwarded-data-from-heavy-forwarder-that/m-p/452930#M78446</guid>
      <dc:creator>damindragunatil</dc:creator>
      <dc:date>2019-07-01T11:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to stop indexing forwarded data from heavy forwarder that indexes locally</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-indexing-forwarded-data-from-heavy-forwarder-that/m-p/452931#M78447</link>
      <description>&lt;P&gt;Where did you read that index-and-forward does not count twice against your license?  I believe that's incorrect,  but would like to see your source.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 12:36:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-indexing-forwarded-data-from-heavy-forwarder-that/m-p/452931#M78447</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-07-01T12:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to stop indexing forwarded data from heavy forwarder that indexes locally</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-indexing-forwarded-data-from-heavy-forwarder-that/m-p/452932#M78448</link>
      <description>&lt;P&gt;Hiya, the source of the answer was here on Splunk Answers&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/337523/does-data-indexed-and-forwarded-from-a-heavy-forwa.html"&gt;https://answers.splunk.com/answers/337523/does-data-indexed-and-forwarded-from-a-heavy-forwa.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;kind regards&lt;/P&gt;

&lt;P&gt;Damindra&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 15:28:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-indexing-forwarded-data-from-heavy-forwarder-that/m-p/452932#M78448</guid>
      <dc:creator>damindragunatil</dc:creator>
      <dc:date>2019-07-01T15:28:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to stop indexing forwarded data from heavy forwarder that indexes locally</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-indexing-forwarded-data-from-heavy-forwarder-that/m-p/452933#M78449</link>
      <description>&lt;P&gt;Thanks for the citation.  That answer has since changed.&lt;BR /&gt;&lt;BR /&gt;
Information on Answers is not official and not always definitive.  See this answer: &lt;A href="https://answers.splunk.com/answers/506909/heavy-forwarder-as-indexer-and-license-usage.html"&gt;https://answers.splunk.com/answers/506909/heavy-forwarder-as-indexer-and-license-usage.html&lt;/A&gt;&lt;BR /&gt;
I'm struggling to find this mentioned in official Splunk docs.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 18:24:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-indexing-forwarded-data-from-heavy-forwarder-that/m-p/452933#M78449</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-07-01T18:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to stop indexing forwarded data from heavy forwarder that indexes locally</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-indexing-forwarded-data-from-heavy-forwarder-that/m-p/452934#M78450</link>
      <description>&lt;P&gt;We recently had this discussion on the Slack usergroups. A heavy forwarder doing indexing is an *&lt;EM&gt;indexer. *&lt;/EM&gt; License usage gets applied when events get written to disk. This means, when you index twice, your license gets hit twice also. &lt;/P&gt;

&lt;P&gt;Skalli&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 19:19:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-indexing-forwarded-data-from-heavy-forwarder-that/m-p/452934#M78450</guid>
      <dc:creator>skalliger</dc:creator>
      <dc:date>2019-07-01T19:19:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to stop indexing forwarded data from heavy forwarder that indexes locally</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-indexing-forwarded-data-from-heavy-forwarder-that/m-p/452935#M78451</link>
      <description>&lt;P&gt;You have no configurations that "filter".  The &lt;CODE&gt;BREAK_ONLY_BEFORE=^CEF\:0\|&lt;/CODE&gt; is a (poorly-performing) LINE_BREAKING configuration.  Even so, I am unclear on your goal.  Please fill out this chart:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| NODE|  IDX?  |  FWD?  |
+-----+--------+--------+
|  HF | YES/NO | YES/NO |
| IDX | YES/NO |   N/A  |
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 06 Jul 2019 03:56:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-indexing-forwarded-data-from-heavy-forwarder-that/m-p/452935#M78451</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-07-06T03:56:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to stop indexing forwarded data from heavy forwarder that indexes locally</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-indexing-forwarded-data-from-heavy-forwarder-that/m-p/452936#M78452</link>
      <description>&lt;P&gt;| NODE|  IDX?  |  FWD?  |&lt;BR /&gt;
2. +-----+--------+--------+&lt;BR /&gt;
3. |  HF | YES/| YES|&lt;BR /&gt;
4. | IDX | YES/ |   N/A  |&lt;/P&gt;

&lt;P&gt;Hope this makes sense, the reason is there needs to be local searching on the HF.&lt;/P&gt;

&lt;P&gt;What would you advise in regards to the LINE_BREAKING?&lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jul 2019 11:19:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-indexing-forwarded-data-from-heavy-forwarder-that/m-p/452936#M78452</guid>
      <dc:creator>damindragunatil</dc:creator>
      <dc:date>2019-07-06T11:19:01Z</dc:date>
    </item>
  </channel>
</rss>

