Getting Data In

Can anyone help me how to configure heavy forwarder?

raghu0479
New Member

I installed the Splunk enterprise on Linux, I used universal forwarder and I could get my logs using it on my Splunk instance, now I want to parse my logs using a heavy forwarder, can anyone help me how to Configure it?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi raghu0479,
I think that you need an Heavy Forwarder because you have different needs than a Universal Forwarder.
Anyway, you have to:

  • install a normal full Splunk Enterprise,
  • go in [Settings -- Forwarding and Receiving]
  • Configure Forwarding -- Default: Store a local copy of forwarded events? NO
  • Configure Forwarding -- Forward Data -- New Forwarding Host: insert hostname:port or IP:port
  • repeat the last configuration for all your indexers
  • system will request a splunk restart

Bye.
Giuseppe

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If the universal forwarder works, why replace it with a heavy forwarder? Performance is better with the UF.

---
If this reply helps you, Karma would be appreciated.
0 Karma

raghu0479
New Member

Hi richgalloway, I have a requirement to use the heavy forwarder, so if you have an idea of how to filter the logs using a heavy forwarder, Please share ur thoughts.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Have you explained to the person who gave you this requirement that a UF performs better than an HF?

You need to give us more to work with. What filtering do you need to do? What logs are you filtering?
You may be better off filtering with syslog-ng or the indexer rather than a heavy forwarder.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...