All Apps and Add-ons

Does NetApp ONTAP 2.0.1 need intermediate forwarders?

Bill_B
Communicator

Hi. I'm trying to deploy the Splunk app for NetApp ONTAP (v. 2.0.1). In the documentation it shows intermediate forwarders for collecting and forwarding NetApp Data ONTAP logs. Here: http://docs.splunk.com/Documentation/NetApp/2.0.1/DeployNetapp/WhataSplunkAppforNetAppDataONTAPdeplo...
Do you actually need these intermediate forwarders or can the NetApp Data ONTAP logs be sent directly to the Splunk Enterprise instance?
Thank you.

1 Solution

martin_mueller
SplunkTrust
SplunkTrust

From a purely functional perspective, your syslog sources can directly send their data to Splunk indexers.

However, it's good practice to have a forwarder between syslog and indexers, running a syslog daemon on the forwarder and reading its logfile. That way you don't lose syslog data during indexer maintenance, e.g. for adding new index-time configuration, and you get a simple way to loadbalance the logs between the indexers.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

From a purely functional perspective, your syslog sources can directly send their data to Splunk indexers.

However, it's good practice to have a forwarder between syslog and indexers, running a syslog daemon on the forwarder and reading its logfile. That way you don't lose syslog data during indexer maintenance, e.g. for adding new index-time configuration, and you get a simple way to loadbalance the logs between the indexers.

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...