Deployment Architecture

How to consider my server acts as a Heavy Forwarder

anandhalagarasa
Path Finder

Hi Team,

We have Splunk Cloud deployed in our environment and we have built an heavy forwarder server. And here we have placed some props and transforms for filtration but actually when i check the data in Splunk Cloud the Regex is not getting applied and hence forth the data seems to be still the improper format so i want to know how to check whether my server is acting as an heavy forwarder or not.

And also how to check whether it is doing a filtering option before indexing in Splunk Cloud.

Kindly let me know on this.

Tags (1)
0 Karma

adonio
Ultra Champion

have always a small instance of splunk that you can fully control - all in 1
on-board the data and tweak your props and transforms accordingly
verify you see the data as you wish, then package your configurations neatly and move them to your Heavy Forwarder

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...