Deployment Architecture

How to install Heavy forwarder and how to configure it in Search header

javvaji
New Member

How to download and install Heavy forwarder and how to configure heavy forwarder in Search header server

Tags (1)
0 Karma

tibevilaqua
Engager

you won't be able to search anything in your Heavy forwarder. As the name implies, it's a forwarder which basically has two functions: Forward the data to an Index/another Heavy Forwarder or even an UF OR ingest data.

In other words, you cannot perform any search against your HF.

0 Karma

dperre_splunk
Splunk Employee
Splunk Employee

Hi There,

What are you trying to achieve? Do you want to be able to search from the Heavy Forwarder? Is the heavy forwarder storing any data or just sending a long? Or would you like to search the contents of the heavy forwarder from another search head?

0 Karma

ChrisG
Splunk Employee
Splunk Employee

Basic docs are here: Deploy a heavy forwarder.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...