<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Deployment architecture in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Deployment-architecture/m-p/385281#M169563</link>
    <description>&lt;P&gt;Theres very specific use cases for using a HF. You should typically let the indexers do the parsing &lt;/P&gt;</description>
    <pubDate>Tue, 08 May 2018 15:17:55 GMT</pubDate>
    <dc:creator>skoelpin</dc:creator>
    <dc:date>2018-05-08T15:17:55Z</dc:date>
    <item>
      <title>Deployment architecture</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Deployment-architecture/m-p/385276#M169558</link>
      <description>&lt;P&gt;I have &lt;BR /&gt;
I want to send windows logs through heavy forwarder to indexer.&lt;/P&gt;

&lt;P&gt;on windows server, I install universal forwarder and put Heavy forwarder ip:9997. &lt;BR /&gt;
already configure listening on heavy forwarder.&lt;/P&gt;

&lt;P&gt;now how can I see event in indexer.&lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2018 14:02:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Deployment-architecture/m-p/385276#M169558</guid>
      <dc:creator>rashid47010</dc:creator>
      <dc:date>2018-05-08T14:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment architecture</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Deployment-architecture/m-p/385277#M169559</link>
      <description>&lt;P&gt;why would you want to use a Heavy Forwarder?&lt;BR /&gt;
try and avoid using HF unless you must have it&lt;BR /&gt;
take a look at this link to troubleshoot:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.0/Troubleshooting/Cantfinddata"&gt;http://docs.splunk.com/Documentation/Splunk/7.1.0/Troubleshooting/Cantfinddata&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2018 14:13:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Deployment-architecture/m-p/385277#M169559</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2018-05-08T14:13:25Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment architecture</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Deployment-architecture/m-p/385278#M169560</link>
      <description>&lt;P&gt;hi &lt;BR /&gt;
this is just a start of completed architecture. &lt;BR /&gt;
However  I achieve this. &lt;BR /&gt;
Now where can  I filter the events&lt;BR /&gt;
on HF OR UF ?&lt;/P&gt;

&lt;P&gt;Please advise.&lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2018 14:31:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Deployment-architecture/m-p/385278#M169560</guid>
      <dc:creator>rashid47010</dc:creator>
      <dc:date>2018-05-08T14:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment architecture</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Deployment-architecture/m-p/385279#M169561</link>
      <description>&lt;P&gt;Did you setup data inputs to collect the data on UF?&lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2018 14:38:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Deployment-architecture/m-p/385279#M169561</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-05-08T14:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment architecture</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Deployment-architecture/m-p/385280#M169562</link>
      <description>&lt;P&gt;Specifically for windows events, you can filter those using whitelist or blacklist settings in inputs.conf on the UF.&lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2018 14:53:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Deployment-architecture/m-p/385280#M169562</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-05-08T14:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment architecture</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Deployment-architecture/m-p/385281#M169563</link>
      <description>&lt;P&gt;Theres very specific use cases for using a HF. You should typically let the indexers do the parsing &lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2018 15:17:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Deployment-architecture/m-p/385281#M169563</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-05-08T15:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment architecture</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Deployment-architecture/m-p/385282#M169564</link>
      <description>&lt;P&gt;Hi Frank,&lt;/P&gt;

&lt;P&gt;Please share some example on this.&lt;/P&gt;</description>
      <pubDate>Wed, 09 May 2018 05:29:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Deployment-architecture/m-p/385282#M169564</guid>
      <dc:creator>rashid47010</dc:creator>
      <dc:date>2018-05-09T05:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment architecture</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Deployment-architecture/m-p/385283#M169565</link>
      <description>&lt;P&gt;Just have a look at the inputs.conf spec and accompanying examples. Or check out my accepted answer here: &lt;A href="https://answers.splunk.com/answers/648353/how-to-limit-a-data-sent-to-indexers-to-only-with.html"&gt;https://answers.splunk.com/answers/648353/how-to-limit-a-data-sent-to-indexers-to-only-with.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 May 2018 07:03:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Deployment-architecture/m-p/385283#M169565</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-05-09T07:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment architecture</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Deployment-architecture/m-p/385284#M169566</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Here is a good reference for your deployment architecture.&lt;BR /&gt;
&lt;A href="http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F" target="_blank"&gt;http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:29:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Deployment-architecture/m-p/385284#M169566</guid>
      <dc:creator>jaracan</dc:creator>
      <dc:date>2020-09-29T19:29:46Z</dc:date>
    </item>
  </channel>
</rss>

