Couple questions about the Splunk Add-on for Box. We're setting up a heavy forwarder to collect the data. Do we need to also install the add-on on both the Search Heads and Indexers as well, or just the Search Heads?
I'm also trying to determine how much disk space is needed on the heavy forwarder VM. Do the Box logs get stored on the heavy forwarder or do they get passed directly to the Indexers, without a copy being saved?
Appreciate the help.
Hi Eric. The installation instructions in the documentation specify that you should install this add-on to your search heads and your heavy forwarder. There is no need to install it on indexers. http://docs.splunk.com/Documentation/AddOns/latest/Box/Install
As for your second question, no, the Box logs are not stored on the heavy forwarder, but they do get parsed there before they are sent on to your indexers. In general, when you think about scaling your forwarders for your data collection tasks, you are considering throughput, not storage. More here: http://docs.splunk.com/Documentation/Splunk/6.3.0/Deploy/Datapipeline
In this case, the Box API has rate limiting, so you are most likely going to be fine with one heavy forwarder.
Also, I am not sure if you are familiar with our Splunk classes, but you might also be interested in checking out the Splunk 6 Administration class. It's an excellent class for getting really familiar with these concepts and applications. There are several prereqs.
Details and upcoming schedule can be found here: