Deployment Architecture

What is the best way to setup forwarding?

mkmur55
New Member

First time Newbie. I have 2 VMs running RHEL 7.4. Both are running the Splunk app. 1 is set for forwarding and 1 for receiving from within the app under "Settings". It looks like it's working but I also see references to Universal Forwarders. What is the best way to go? This is just for learning purposes.

Thanks

Mike Murphy

0 Karma

skoelpin
SplunkTrust
SplunkTrust

The remote server that is forwarding data should have a Universal Forwarder installed and the server that is receiving the data should have a full Splunk Enterprise install

Here's info for the Universal Forwarder

http://docs.splunk.com/Documentation/Forwarder/7.0.3/Forwarder/Configuretheuniversalforwarder

0 Karma

sloshburch
Splunk Employee
Splunk Employee

To build on this, while "best" is an "it depends" provoking question, I want to share with you that when I first started playing with Splunk, I also started with the classic full Splunk Enterprise install. Only after learning more and understanding the differences in forwarder types was I able to make a more informed choice to switch to the Universal Forwarder.

So, there's nothing "wrong" with what you're doing. I suggest, as you get more comfortable, read some of this material to learn more about the choices you are able to make, should you choose to make them.

Also, take a peek at the system requirements for Splunk on VMs. Those VMs are probably fine to play with but there's things to consider and min specs to get to when it's time to party in production.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...