All Apps and Add-ons

What is being forwarded when DB Connect 3 is installed on Heavy Forwarder?

grittonc
Contributor

There are many other excellent answers here about configuring DB Connect on an HF. However, I am curious about what is being forwarded.

I've done plenty of work with Universal Forwarders sending logs or .csv files. Does DB Connect generate files that are then forwarded? Or does the data forwarding happen without files because of what's in the outputs.conf? I'd love it if someone could explain.

0 Karma
1 Solution

grittonc
Contributor

After setting up my own HF, it looks like as long as the SplunkForwarder app is enabled and the receiving instance has been added to the list in "Configure Forwarding", the data forwarding happens without files because of what's in outputs.conf.

The indexes that you want to contain the data on your receiving instance don't even have to exist on the HF, and the HF default setting doesn't index any data.

This is the answer I was looking for. I hope it helps someone in the future.

View solution in original post

0 Karma

grittonc
Contributor

After setting up my own HF, it looks like as long as the SplunkForwarder app is enabled and the receiving instance has been added to the list in "Configure Forwarding", the data forwarding happens without files because of what's in outputs.conf.

The indexes that you want to contain the data on your receiving instance don't even have to exist on the HF, and the HF default setting doesn't index any data.

This is the answer I was looking for. I hope it helps someone in the future.

0 Karma

jcoates
Communicator
0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...