Getting Data In

Can anyone help me how to configure heavy forwarder?

raghu0479
New Member

I installed the Splunk enterprise on Linux, I used universal forwarder and I could get my logs using it on my Splunk instance, now I want to parse my logs using a heavy forwarder, can anyone help me how to Configure it?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi raghu0479,
I think that you need an Heavy Forwarder because you have different needs than a Universal Forwarder.
Anyway, you have to:

  • install a normal full Splunk Enterprise,
  • go in [Settings -- Forwarding and Receiving]
  • Configure Forwarding -- Default: Store a local copy of forwarded events? NO
  • Configure Forwarding -- Forward Data -- New Forwarding Host: insert hostname:port or IP:port
  • repeat the last configuration for all your indexers
  • system will request a splunk restart

Bye.
Giuseppe

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If the universal forwarder works, why replace it with a heavy forwarder? Performance is better with the UF.

---
If this reply helps you, Karma would be appreciated.
0 Karma

raghu0479
New Member

Hi richgalloway, I have a requirement to use the heavy forwarder, so if you have an idea of how to filter the logs using a heavy forwarder, Please share ur thoughts.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Have you explained to the person who gave you this requirement that a UF performs better than an HF?

You need to give us more to work with. What filtering do you need to do? What logs are you filtering?
You may be better off filtering with syslog-ng or the indexer rather than a heavy forwarder.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...