Deployment Architecture

Heavy forwarder without indexing

troyfred
Explorer

So we have a client who has a splunk deployment already. They are not for using the universal forwarder to send us certain logs while their deployment also gets every index they are reporting on. The suggestion we got was to use a heavy forwarder to send all index's to them and have the heavy forwarder send just the two or three index's we are looking for to us. Most of the heavy forwarder comments though use an index and forward method, but the client wants to use their indexer and not have it basically indexed twice. Another of the issues is that the client already sends EVERYTHING as it's own index, (IE security logs = security index, application = application index etc). Any assistance would be greatly appreciated.

Labels (1)
0 Karma

nwuest
Path Finder

Hi @troyfred,

I see you are trying to work with a client on utilizing a heavy forwarder without indexing.

On the topic of the client wanting to use "Their Heavy Forwarder" vs. a Universal Forwarder:

I'm unsure how firm your client is with wanting to utilize a Heavy Forwarder over a Universal Forwarder but here is an article that is a great read on the differences between the two. Definitely keep the dialog open between you and the client so you can offer suggestions/solutions to their current challenges.
Universal or Heavy, that is the question?  

On the topic of "Index and Forward" for the Heavy Forwarders:

Heavy Forwarders will typically only take data in and forward it on to its target environment/machine. If your client does not want to "Index" data twice, once at the Heavy Forwarder and again at the Indexer, they need to not include the "indexAndForward = true" setting in the tcpout stanza of the outputs.conf file.

[tcpout]
indexAndForward=true

View solution in original post 

On the topic of sending over only "selective" indexes:

Route and filter data 

I do hope these articles / comments / suggestions work for you. Please comment back to know how this dialog progresses with you and your client!

V/R,
nwuest

 

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...