Getting Data In

Benefits of Using a Forwarder?

ConnorG
Path Finder

Could someone explain the benefits of using a forwarder?

The main benefits explained in the doc (data consolidation, load balancing, and data routing) are not related to the setup my team is planning as we only have one source directly pushing events to Splunk.

Corollary question: does using a heavy forwarder take more stress off the receiver compared to a light forwarder?

Tags (1)
0 Karma

ddrillic
Ultra Champion

The lovely book – "Big Data Analytics Using Splunk" says on page #286 -

"Whereas the data collected by forwarders contains the standard Splunk fields (host, source and source type), which makes for easy categorization, these fields might not be enough to catalog data. For example, when collecting Windows WMI events, you might want to separate hardware from software events, so that they can be analyzed by the appropriate technical people. "

So, the heavy forwarder has more capabilities to process the incoming data.

Regards,
Dan

thomrs
Communicator

We use a forwarder to collect al out syslog data from the syslog server. We opted to keep the syslog server and use a UF to we could work on splunk, i.e. restart and not worry about loosing data during the restart. The UF will cache the data until it can send it to the indexer.

The HF can do some processing on the data then send it to the indexer. So yes it could help, I've never had a reason to do that. I'd suggest you look at the SOS and deployment apps to help monitor things.

https://apps.splunk.com/app/748/
https://apps.splunk.com/app/1294/

The other reason I like not going directly to splunk is if there is an issue that affects splunk my logs still are in flat files on the server.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...