All Apps and Add-ons

Where do I install the JMS Modular Input in my environment (indexer or forwarder)?

lyndac
Contributor

I have an environment which has a search head, two indexers and a forwarder. Where do I install the JMS Modular Input? pick an indexer? the forwarder?

Assuming I install on an indexer, will there be any contention with the data being received by the forwarder?

Thanks!

0 Karma
1 Solution

jmallorquin
Builder

Hi,

A good implementation could be install a heavy forwarder instance in the forwarder machine and install the JMS in this one.

Hope help you

View solution in original post

jmallorquin
Builder

Hi,

A good implementation could be install a heavy forwarder instance in the forwarder machine and install the JMS in this one.

Hope help you

laytonj76
Explorer

This post was helpful as I'm researching the JMS TA since we have inherited an existing set up using it. I have a follow up to this question. In my customer's current implementation, the TA was manually installed on all 3 of our indexers instead of on a forwarder. We're now seeing indexing issues (i.e. only 1 of our 3 indexers is actively ingesting per the DMC). Do you think the TA manually installed on the 3 indexers could be the issue?

By the way, we are planning to move from this current implementation to utilize a heavy forwarder as recommended; we just want to develop a clear understanding of why we'd see the indexer issues we're seeing.

0 Karma

Damien_Dallimor
Ultra Champion

That is the correct approach.

0 Karma

lyndac
Contributor

why heavy forwarder vs. universal forwarder?

0 Karma

Damien_Dallimor
Ultra Champion

either is fine.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...