<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder to Intermediate Forwarding  to Splunk Enterprise Instance,Indexer Cluster &amp;amp; Heavy Forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-to-Intermediate-Forwarding-to-Splunk/m-p/508992#M86576</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223614"&gt;@hectorvp&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I use IFs only when I have UFs in separate networks so I don't want to open too many routes between targets and Indexers (especially if I have to use Splunk Cloud!).&lt;/P&gt;&lt;P&gt;If there isn't this requirement I usually send logs from targets to Indexers.&lt;/P&gt;&lt;P&gt;IFs could be a bottleneck (it depends on the log volume and configurations) and anyway they are an additional complication to architecture, so, if there isn't an explicit requirement I don't use them!&lt;/P&gt;&lt;P&gt;About indexing costing, they are indipendent from the presence of IFs, it depends only on the volume of indexed logs.&lt;/P&gt;&lt;P&gt;To better understand and create your architecture, the best approach is to have in your team a Splunk Architect from your System Integrator or a Splunk PS.&lt;/P&gt;&lt;P&gt;In addition I suggest the Splunk Architect Certification Path that's very useful for this.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jul 2020 07:18:25 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2020-07-14T07:18:25Z</dc:date>
    <item>
      <title>Universal Forwarder to Intermediate Forwarding  to Splunk Enterprise Instance,Indexer Cluster &amp; Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-to-Intermediate-Forwarding-to-Splunk/m-p/508621#M86525</link>
      <description>&lt;P&gt;I've a scenario where I've got around 250 servers where UF has to be installed. These data would be forwarded to Indexer cluster or heavy forwarder via Intermediate Forwarder.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to use Intermediate forwarder(Universal forwarder itself).&lt;/P&gt;&lt;P&gt;Now I need to route data from Intermediate Forwarder in this way:&lt;/P&gt;&lt;P&gt;if hostname=x&lt;/P&gt;&lt;P&gt;( Indexer Cluster&amp;nbsp; AND Other Splunk Enterprise Instance)&amp;nbsp;&lt;/P&gt;&lt;P&gt;else if hostname=y&lt;/P&gt;&lt;P&gt;(Heay Forwarder AND Other Splunk Enterprise Instance)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: Splunk Enterprise Instance is other independent instance which has no relation with Indexer cluster and heavy forwarder)&lt;/P&gt;&lt;P&gt;What should by inputs.conf &amp;amp; outputs.conf in UF and Intermediate Forwarder?&lt;/P&gt;&lt;P&gt;How can I achieve this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jul 2020 18:28:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-to-Intermediate-Forwarding-to-Splunk/m-p/508621#M86525</guid>
      <dc:creator>hectorvp</dc:creator>
      <dc:date>2020-07-11T18:28:40Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder to Intermediate Forwarding  to Splunk Enterprise Instance,Indexer Cluster &amp; Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-to-Intermediate-Forwarding-to-Splunk/m-p/508668#M86531</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223614"&gt;@hectorvp&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you have only to forward logs, you can use a Universal Forwarder as intermediate Forwarder, but, if you have to make some eleboration (e.g. choose the destination indexer) you have to use an Heavy Forwarder as Intermediate Forwarder (remeber that in this way you have to do parsing and transformation in this HF).&lt;/P&gt;&lt;P&gt;But i think that the correct approach should be another:&lt;/P&gt;&lt;P&gt;I think that you manage your Universal Forwarders using a Deployment Server.&lt;/P&gt;&lt;P&gt;So you could create two apps (called e.g. TA_ForwardersX and TA_ForwardersY) in which you put only two files:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;deploymentclient.conf, addressing your Deployment Server: it will be the same in both the TAs;&lt;/LI&gt;&lt;LI&gt;outputs.conf addressing, the indexers to send data: they will be specific for each TA.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;In the first outputs.conf you use the destinations for hostnames=x and put it in TA_ForwardersX.&lt;/P&gt;&lt;P&gt;In the second you&amp;nbsp;put the destinations for hostnames=y and put it in TA_ForwardersY.&lt;/P&gt;&lt;P&gt;Then you create two ServerClasses so you'll have your correct distribution.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jul 2020 08:47:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-to-Intermediate-Forwarding-to-Splunk/m-p/508668#M86531</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-12T08:47:51Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder to Intermediate Forwarding  to Splunk Enterprise Instance,Indexer Cluster &amp; Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-to-Intermediate-Forwarding-to-Splunk/m-p/508893#M86565</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;Thanks afa lot for replying&lt;/P&gt;&lt;P&gt;this provided solution sends logs directly to indexer right? And no IF right?&lt;/P&gt;&lt;P&gt;Actually I've to use IF which is UF due to the business requirement, what I've thought is to make IF listen on two different ports where port 1 will receive host x logs and port 2 will receive host y logs then I can forward them...I knw this isn't a best way but I guess this will work....&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Since I'm new with splunk and I've other questions as well,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I've around 250 servers where only OS logs has to be collected and no application logs which would be send to IF,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Use of 2 IF will cause bottleneck or it won't??? Or do I've to add more??&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And how much data would be ingested to indexer so I can estimate costing for this??&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;These are very practical scenarios where it is difficult to find answers in documentation or anywhere, your reply would really help.....&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 19:21:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-to-Intermediate-Forwarding-to-Splunk/m-p/508893#M86565</guid>
      <dc:creator>hectorvp</dc:creator>
      <dc:date>2020-07-13T19:21:20Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder to Intermediate Forwarding  to Splunk Enterprise Instance,Indexer Cluster &amp; Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-to-Intermediate-Forwarding-to-Splunk/m-p/508992#M86576</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223614"&gt;@hectorvp&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I use IFs only when I have UFs in separate networks so I don't want to open too many routes between targets and Indexers (especially if I have to use Splunk Cloud!).&lt;/P&gt;&lt;P&gt;If there isn't this requirement I usually send logs from targets to Indexers.&lt;/P&gt;&lt;P&gt;IFs could be a bottleneck (it depends on the log volume and configurations) and anyway they are an additional complication to architecture, so, if there isn't an explicit requirement I don't use them!&lt;/P&gt;&lt;P&gt;About indexing costing, they are indipendent from the presence of IFs, it depends only on the volume of indexed logs.&lt;/P&gt;&lt;P&gt;To better understand and create your architecture, the best approach is to have in your team a Splunk Architect from your System Integrator or a Splunk PS.&lt;/P&gt;&lt;P&gt;In addition I suggest the Splunk Architect Certification Path that's very useful for this.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 07:18:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-to-Intermediate-Forwarding-to-Splunk/m-p/508992#M86576</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-14T07:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder to Intermediate Forwarding  to Splunk Enterprise Instance,Indexer Cluster &amp; Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-to-Intermediate-Forwarding-to-Splunk/m-p/511201#M86825</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot for your guidance, surely I've certification in my roadmap, however things are changing rapidly here in my organisation so not able to reach out splunk professional consultant.&lt;/P&gt;&lt;P&gt;I was able to explain stakeholders not to use IF&amp;nbsp; as they were adding unnecessary overhead in a design.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm right now calculating&amp;nbsp; splunk license sizing and these are my calculations, please suggest incase I'm going wrong:&lt;/P&gt;&lt;P&gt;Total servers : 250&lt;/P&gt;&lt;P&gt;Expected license : 10GB&lt;/P&gt;&lt;P&gt;Each server gets 40MB of logs to get ingested in indexer daily,&lt;/P&gt;&lt;P&gt;Most of the servers are windows server and requirement is to only pull OS logs(system, security, application,setup) and no application logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Considering each event size as 700bytes.&lt;/P&gt;&lt;P&gt;So total events one server can have at every day= 40* 10^6 / 700 =&amp;nbsp; 57,142.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know event size and no. of events changes from server to server but this is how I'm planning to estimate it.&lt;/P&gt;&lt;P&gt;Avg event size for windows is 500bytes as per I saw over internet and I've added 200 bytes as a buffer or for normalisation.&lt;/P&gt;&lt;P&gt;So is this calculation in a right way?&lt;/P&gt;&lt;P&gt;Am i missing something?&lt;/P&gt;&lt;P&gt;Practically&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm in no position to make a POC to find right estimates perhaps I can check no. of events generated per day on one of the 250 servers.&lt;/P&gt;&lt;P&gt;And can revise&amp;nbsp; my license&amp;nbsp; capacity prior to procuring it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 18:31:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-to-Intermediate-Forwarding-to-Splunk/m-p/511201#M86825</guid>
      <dc:creator>hectorvp</dc:creator>
      <dc:date>2020-07-27T18:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder to Intermediate Forwarding  to Splunk Enterprise Instance,Indexer Cluster &amp; Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-to-Intermediate-Forwarding-to-Splunk/m-p/511270#M86845</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223614"&gt;@hectorvp&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I understand your needs, we're all in the same situation, but anyway don't&amp;nbsp; forget training and certifications (it's very useful also for you!).&lt;/P&gt;&lt;P&gt;Anyway, if you have 40 MB/day for each server, the total license consuption (in GB/day) is 40*250/1024, then you have to consider a 25/30% of additional license because you could have some extraordinary days.&lt;/P&gt;&lt;P&gt;Sincerely I think that 40 MB/day for a windows server are really few because a windows server has normally more than 20,000 events by day and Domain Controllers much more than.&lt;/P&gt;&lt;P&gt;But anyway you can identify them in a PoC, using at least one server and one DC.&lt;/P&gt;&lt;P&gt;If you cannot do a PoC, you could consider 40-50 MB/day per server (eventually filtering non interesting events) and 200 MB/day for the domain controllers.&lt;/P&gt;&lt;P&gt;Then As I said, consider 25% of margin.&lt;/P&gt;&lt;P&gt;Then, remeber that if you want to monitor file servers, they are very verbose!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 07:10:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-to-Intermediate-Forwarding-to-Splunk/m-p/511270#M86845</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-28T07:10:50Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder to Intermediate Forwarding  to Splunk Enterprise Instance,Indexer Cluster &amp; Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-to-Intermediate-Forwarding-to-Splunk/m-p/511313#M86851</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;:&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot again for these responses, it is really helping me a lot.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 12:01:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-to-Intermediate-Forwarding-to-Splunk/m-p/511313#M86851</guid>
      <dc:creator>hectorvp</dc:creator>
      <dc:date>2020-07-28T12:01:44Z</dc:date>
    </item>
  </channel>
</rss>

