Deployment Architecture

How to consider my server acts as a Heavy Forwarder

anandhalagarasa
Path Finder

Hi Team,

We have Splunk Cloud deployed in our environment and we have built an heavy forwarder server. And here we have placed some props and transforms for filtration but actually when i check the data in Splunk Cloud the Regex is not getting applied and hence forth the data seems to be still the improper format so i want to know how to check whether my server is acting as an heavy forwarder or not.

And also how to check whether it is doing a filtering option before indexing in Splunk Cloud.

Kindly let me know on this.

Tags (1)
0 Karma

adonio
Ultra Champion

have always a small instance of splunk that you can fully control - all in 1
on-board the data and tweak your props and transforms accordingly
verify you see the data as you wish, then package your configurations neatly and move them to your Heavy Forwarder

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...