Getting Data In

Can a Universal Forwarder be used to forward indexed data on a search head to an indexer?

Ryan_Beck
Engager

Hello. I'm fairly new to Splunk and am working on configuring a Splunk infrastructure. If I have one search head server and one indexer server, any data that is indexed on the search head server should be forwarded to the indexer server. I see that there are Splunk documents that show to change the outputs.conf file to accomplish this.

However, instead of changing the outputs.conf file, could I install a universal forwarder on the search head server and use the universal forwarder to forward all indexed data to the indexer server?

I would appreciate any insight.

0 Karma
1 Solution

sk314
Builder

The search head is full Splunk Enterprise instance and includes ALL features including the forwarder features. You do not have to install a forwarder additionally. Use the outputs.conf settings to forward the data. It's a best practice. This helps you analyze the internal logs even if your search head is down.

For Reference: http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/Forwardsearchheaddata

View solution in original post

sk314
Builder

The search head is full Splunk Enterprise instance and includes ALL features including the forwarder features. You do not have to install a forwarder additionally. Use the outputs.conf settings to forward the data. It's a best practice. This helps you analyze the internal logs even if your search head is down.

For Reference: http://docs.splunk.com/Documentation/Splunk/6.5.0/DistSearch/Forwardsearchheaddata

Ryan_Beck
Engager

Ok I see, that makes sense and clarifies things. Thank you for your reply and the information that you provided!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...