All Apps and Add-ons

What is being forwarded when DB Connect 3 is installed on Heavy Forwarder?

grittonc
Contributor

There are many other excellent answers here about configuring DB Connect on an HF. However, I am curious about what is being forwarded.

I've done plenty of work with Universal Forwarders sending logs or .csv files. Does DB Connect generate files that are then forwarded? Or does the data forwarding happen without files because of what's in the outputs.conf? I'd love it if someone could explain.

0 Karma
1 Solution

grittonc
Contributor

After setting up my own HF, it looks like as long as the SplunkForwarder app is enabled and the receiving instance has been added to the list in "Configure Forwarding", the data forwarding happens without files because of what's in outputs.conf.

The indexes that you want to contain the data on your receiving instance don't even have to exist on the HF, and the HF default setting doesn't index any data.

This is the answer I was looking for. I hope it helps someone in the future.

View solution in original post

0 Karma

grittonc
Contributor

After setting up my own HF, it looks like as long as the SplunkForwarder app is enabled and the receiving instance has been added to the list in "Configure Forwarding", the data forwarding happens without files because of what's in outputs.conf.

The indexes that you want to contain the data on your receiving instance don't even have to exist on the HF, and the HF default setting doesn't index any data.

This is the answer I was looking for. I hope it helps someone in the future.

0 Karma

jcoates
Communicator
0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...