<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Heavy Forwarder Configuration Query in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Heavy-Forwarder-Configuration-Query/m-p/490684#M8317</link>
    <description>&lt;P&gt;Hi @spodda01da,&lt;BR /&gt;
Heavy Forwarders are useful in these situations:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;if you have to ingest syslogs,&lt;/LI&gt;
&lt;LI&gt;if you have a part of your Universal Forwarders in a separate network and you don't  want to open all the firewall routes between targets and Indexers,&lt;/LI&gt;
&lt;LI&gt;if you have a great parsing job and you want to reduce load on Indexers.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;For my experience, only the first two options really justify the use of an Heavy Forwarder, for the third, I prefer to add more resources to Indexers or ad an Indexer then add an Heavy Forwearder.&lt;/P&gt;

&lt;P&gt;In addition remember that, when you decide to use an Heavy Forwarder, you have always to duplicate it to avoid a Single Points of Failure and you have to carefully configure them to avoid bottlenecks.&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 18 Nov 2019 08:07:07 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2019-11-18T08:07:07Z</dc:date>
    <item>
      <title>Heavy Forwarder Configuration Query</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Heavy-Forwarder-Configuration-Query/m-p/490682#M8315</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I have inherited Splunk Enterprise in my company which includes 3 Indexers, 2 Search Head and each Deployment &amp;amp; Licensing Master and Cluster Master.&lt;/P&gt;

&lt;P&gt;Now in order to receive events from more than 250 servers, Do I need to setup a separate Heavy Forwarder (server) or can we use the above setup/configuration and use one of them as heavy forwarder.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2019 06:17:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Heavy-Forwarder-Configuration-Query/m-p/490682#M8315</guid>
      <dc:creator>spodda01da</dc:creator>
      <dc:date>2019-11-18T06:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder Configuration Query</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Heavy-Forwarder-Configuration-Query/m-p/490683#M8316</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Using HF in your current setup depends, how much data you are indexing per day? your budget&lt;BR /&gt;
HF will reduce performing impact on Indexers , it helps you to parse,filter, can index locally and with many other benefits.&lt;BR /&gt;
Please refer the documentation &lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.0/Forwarding/Typesofforwarders"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.0/Forwarding/Typesofforwarders&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If you need all these benefits then you should consider having HFs in your environment&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2019 07:05:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Heavy-Forwarder-Configuration-Query/m-p/490683#M8316</guid>
      <dc:creator>sanjeev543</dc:creator>
      <dc:date>2019-11-18T07:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder Configuration Query</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Heavy-Forwarder-Configuration-Query/m-p/490684#M8317</link>
      <description>&lt;P&gt;Hi @spodda01da,&lt;BR /&gt;
Heavy Forwarders are useful in these situations:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;if you have to ingest syslogs,&lt;/LI&gt;
&lt;LI&gt;if you have a part of your Universal Forwarders in a separate network and you don't  want to open all the firewall routes between targets and Indexers,&lt;/LI&gt;
&lt;LI&gt;if you have a great parsing job and you want to reduce load on Indexers.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;For my experience, only the first two options really justify the use of an Heavy Forwarder, for the third, I prefer to add more resources to Indexers or ad an Indexer then add an Heavy Forwearder.&lt;/P&gt;

&lt;P&gt;In addition remember that, when you decide to use an Heavy Forwarder, you have always to duplicate it to avoid a Single Points of Failure and you have to carefully configure them to avoid bottlenecks.&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2019 08:07:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Heavy-Forwarder-Configuration-Query/m-p/490684#M8317</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-11-18T08:07:07Z</dc:date>
    </item>
  </channel>
</rss>

