<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Heavy Forward in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forward/m-p/492158#M84126</link>
    <description>&lt;P&gt;Hi Gcusello&lt;BR /&gt;
I see this message on my entire datamodel, how can I fix it?&lt;BR /&gt;
"This object has no explicit index constraint. Consider adding one for better performance."&lt;/P&gt;</description>
    <pubDate>Wed, 02 Oct 2019 23:15:20 GMT</pubDate>
    <dc:creator>vumanhtai</dc:creator>
    <dc:date>2019-10-02T23:15:20Z</dc:date>
    <item>
      <title>Heavy Forward</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forward/m-p/492154#M84122</link>
      <description>&lt;P&gt;hello Splunk Team&lt;BR /&gt;
i want to config Heavy Forward to receive and index then send data to my cluster index?&lt;BR /&gt;
Thank ALL&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2019 13:34:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forward/m-p/492154#M84122</guid>
      <dc:creator>vumanhtai</dc:creator>
      <dc:date>2019-10-02T13:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forward</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forward/m-p/492155#M84123</link>
      <description>&lt;P&gt;Hi vumanhtai,&lt;BR /&gt;
to configure your Heavy Forwarder, you have to go in [Settings -- Forwarding and Receiving]&lt;BR /&gt;
Then use [Forwardering Defaults] to say to locally index and forward.&lt;BR /&gt;
Then use [Configure Forwarding] to say to the HF wht are the indexers to send logs.&lt;BR /&gt;
Splunk will ask to restart itself.&lt;/P&gt;

&lt;P&gt;Only one question: why do you want to locally index logs?&lt;BR /&gt;
In this way you pay twice license and you don't need of local logs because you have the Indexers Cluster for searches.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2019 13:41:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forward/m-p/492155#M84123</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-10-02T13:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forward</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forward/m-p/492156#M84124</link>
      <description>&lt;P&gt;Thank You so much!&lt;BR /&gt;
Can you give me your contact information?&lt;BR /&gt;
I have run out of working hours and I want to contact you at another time.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2019 13:51:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forward/m-p/492156#M84124</guid>
      <dc:creator>vumanhtai</dc:creator>
      <dc:date>2019-10-02T13:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forward</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forward/m-p/492157#M84125</link>
      <description>&lt;P&gt;Continue to use the Community, in this way, your questions and answers will be useful also for other people and you can be helped also by other friends.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2019 13:59:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forward/m-p/492157#M84125</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-10-02T13:59:29Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forward</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forward/m-p/492158#M84126</link>
      <description>&lt;P&gt;Hi Gcusello&lt;BR /&gt;
I see this message on my entire datamodel, how can I fix it?&lt;BR /&gt;
"This object has no explicit index constraint. Consider adding one for better performance."&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2019 23:15:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forward/m-p/492158#M84126</guid>
      <dc:creator>vumanhtai</dc:creator>
      <dc:date>2019-10-02T23:15:20Z</dc:date>
    </item>
  </channel>
</rss>

