There are many other excellent answers here about configuring DB Connect on an HF. However, I am curious about what is being forwarded.
I've done plenty of work with Universal Forwarders sending logs or .csv files. Does DB Connect generate files that are then forwarded? Or does the data forwarding happen without files because of what's in the outputs.conf? I'd love it if someone could explain.
After setting up my own HF, it looks like as long as the SplunkForwarder app is enabled and the receiving instance has been added to the list in "Configure Forwarding", the data forwarding happens without files because of what's in outputs.conf.
The indexes that you want to contain the data on your receiving instance don't even have to exist on the HF, and the HF default setting doesn't index any data.
This is the answer I was looking for. I hope it helps someone in the future.
After setting up my own HF, it looks like as long as the SplunkForwarder app is enabled and the receiving instance has been added to the list in "Configure Forwarding", the data forwarding happens without files because of what's in outputs.conf.
The indexes that you want to contain the data on your receiving instance don't even have to exist on the HF, and the HF default setting doesn't index any data.
This is the answer I was looking for. I hope it helps someone in the future.