All Apps and Add-ons

MS Exchange App - Heavy Forwarder

adrianathome
Communicator

What is the point of the heavy forwarder outlined in step 4 of the docs?

  1. Next, install a full Splunk instance that has an outbound connection to the Internet. Note: This server should be separate from the central Splunk App for Microsoft Exchange instance and any Exchange servers which also run universal forwarders.

Is that heavy forwarder doing anything that can't be done at the indexer?

0 Karma

jbernt_splunk
Splunk Employee
Splunk Employee

This step is for the TA-SMTP-reputation component (as per step 6) since a full Splunk install has the required Python components to check SMTP server reputation. Keep in mind that this heavy forwarder install will take up resources separate from your indexing tier. Installing the TA-SMTP-Reputation component on your indexing tier is not supported. Another option is to install a heavy forwarder on one of your Exchange servers to handle this requirement, but again, not recommended due to resource requirements.
Thanks,
Jeff.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...