All Apps and Add-ons

Where do I install the JMS Modular Input in my environment (indexer or forwarder)?

lyndac
Contributor

I have an environment which has a search head, two indexers and a forwarder. Where do I install the JMS Modular Input? pick an indexer? the forwarder?

Assuming I install on an indexer, will there be any contention with the data being received by the forwarder?

Thanks!

0 Karma
1 Solution

jmallorquin
Builder

Hi,

A good implementation could be install a heavy forwarder instance in the forwarder machine and install the JMS in this one.

Hope help you

View solution in original post

jmallorquin
Builder

Hi,

A good implementation could be install a heavy forwarder instance in the forwarder machine and install the JMS in this one.

Hope help you

laytonj76
Explorer

This post was helpful as I'm researching the JMS TA since we have inherited an existing set up using it. I have a follow up to this question. In my customer's current implementation, the TA was manually installed on all 3 of our indexers instead of on a forwarder. We're now seeing indexing issues (i.e. only 1 of our 3 indexers is actively ingesting per the DMC). Do you think the TA manually installed on the 3 indexers could be the issue?

By the way, we are planning to move from this current implementation to utilize a heavy forwarder as recommended; we just want to develop a clear understanding of why we'd see the indexer issues we're seeing.

0 Karma

Damien_Dallimor
Ultra Champion

That is the correct approach.

0 Karma

lyndac
Contributor

why heavy forwarder vs. universal forwarder?

0 Karma

Damien_Dallimor
Ultra Champion

either is fine.

0 Karma
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf24, and Community Connections

Thank you to everyone in the Splunk Community who joined us for .conf24 – starting with Splunk University and ...

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...