<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Indexer vs universal forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-vs-universal-forwarder/m-p/515678#M87315</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;I have a remote file (on&amp;nbsp; server 2) which can be accessed directly from my Indexer (on server 1). What is the best and recommended way to ingest data from that file into indexer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Read directly from indexer's inputs.conf (monitor://remote-path to the file) - Everything on server 1&lt;/P&gt;&lt;P&gt;2) Install universal forwarder on the target machine and forward data (complete log file. no props and transforms) - indexer on server1 and forwarder on server 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Whats the main difference between these 2 options? pros and cons?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 24 Aug 2020 03:31:15 GMT</pubDate>
    <dc:creator>nareshinsvu</dc:creator>
    <dc:date>2020-08-24T03:31:15Z</dc:date>
    <item>
      <title>Indexer vs universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-vs-universal-forwarder/m-p/515678#M87315</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;I have a remote file (on&amp;nbsp; server 2) which can be accessed directly from my Indexer (on server 1). What is the best and recommended way to ingest data from that file into indexer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Read directly from indexer's inputs.conf (monitor://remote-path to the file) - Everything on server 1&lt;/P&gt;&lt;P&gt;2) Install universal forwarder on the target machine and forward data (complete log file. no props and transforms) - indexer on server1 and forwarder on server 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Whats the main difference between these 2 options? pros and cons?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2020 03:31:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-vs-universal-forwarder/m-p/515678#M87315</guid>
      <dc:creator>nareshinsvu</dc:creator>
      <dc:date>2020-08-24T03:31:15Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer vs universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-vs-universal-forwarder/m-p/515697#M87317</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/156769"&gt;@nareshinsvu&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you have a little confusion:&lt;/P&gt;&lt;P&gt;props.conf and transforms.conf are on Indexer in both cases because they work in the parsing, merging and typing phases.&lt;/P&gt;&lt;P&gt;Instead inputs.conf depends on the choose you're working.&lt;/P&gt;&lt;P&gt;There're only one exception to this rule: in the input of csv files, props.conf must be also on Forwarder.&lt;/P&gt;&lt;P&gt;Anyway, answering to your question: if possible using a Universal Forwarder on the target server is the best approach because you optimize the input phase and the network bandwidth.&lt;/P&gt;&lt;P&gt;In addition (if you like) you can encrypt transmission.&lt;/P&gt;&lt;P&gt;The other solution is to use if you cannot install the UF on the target server: e.g. it's an old operative system or there aren't resources or simply you don't want to install nothing on it.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2020 06:23:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-vs-universal-forwarder/m-p/515697#M87317</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-08-24T06:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer vs universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-vs-universal-forwarder/m-p/515706#M87319</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/156769"&gt;@nareshinsvu&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Good!&lt;/P&gt;&lt;P&gt;ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2020 07:36:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-vs-universal-forwarder/m-p/515706#M87319</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-08-24T07:36:19Z</dc:date>
    </item>
  </channel>
</rss>

