Deployment Architecture

How to consider my server acts as a Heavy Forwarder

anandhalagarasa
Path Finder

Hi Team,

We have Splunk Cloud deployed in our environment and we have built an heavy forwarder server. And here we have placed some props and transforms for filtration but actually when i check the data in Splunk Cloud the Regex is not getting applied and hence forth the data seems to be still the improper format so i want to know how to check whether my server is acting as an heavy forwarder or not.

And also how to check whether it is doing a filtering option before indexing in Splunk Cloud.

Kindly let me know on this.

Tags (1)
0 Karma

adonio
Ultra Champion

have always a small instance of splunk that you can fully control - all in 1
on-board the data and tweak your props and transforms accordingly
verify you see the data as you wish, then package your configurations neatly and move them to your Heavy Forwarder

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...