All Apps and Add-ons

What is being forwarded when DB Connect 3 is installed on Heavy Forwarder?

grittonc
Contributor

There are many other excellent answers here about configuring DB Connect on an HF. However, I am curious about what is being forwarded.

I've done plenty of work with Universal Forwarders sending logs or .csv files. Does DB Connect generate files that are then forwarded? Or does the data forwarding happen without files because of what's in the outputs.conf? I'd love it if someone could explain.

0 Karma
1 Solution

grittonc
Contributor

After setting up my own HF, it looks like as long as the SplunkForwarder app is enabled and the receiving instance has been added to the list in "Configure Forwarding", the data forwarding happens without files because of what's in outputs.conf.

The indexes that you want to contain the data on your receiving instance don't even have to exist on the HF, and the HF default setting doesn't index any data.

This is the answer I was looking for. I hope it helps someone in the future.

View solution in original post

0 Karma

grittonc
Contributor

After setting up my own HF, it looks like as long as the SplunkForwarder app is enabled and the receiving instance has been added to the list in "Configure Forwarding", the data forwarding happens without files because of what's in outputs.conf.

The indexes that you want to contain the data on your receiving instance don't even have to exist on the HF, and the HF default setting doesn't index any data.

This is the answer I was looking for. I hope it helps someone in the future.

0 Karma

jcoates
Communicator
0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...