I have this workflow
I'm using this HF just to route the data to Splunk clould without any indexing locally, but with few regexes for filtering in props and transforms. When i tried to login to HF GUI there was a message prompted to upgrade the license.
Can i convert that HF to a slave or a Free license..?
It depends, will you ever want to use indexing on the HF or authentication?
If not, then use a forwarder license.
I don't want to use indexing on HF, but still i have some regexs in props and transforms to filter/restrict/mask some of the data before sending it to cloud.
-do i need to convert it to slave or a free license would be fine..?
A forwarding license will use these transformations as the HF will still parse the information.
So a forwarding license will work fine. You could also send your Transforms and Props to the SplunkCloud team and then your indexers can do the work, eliminating the need for a HF 🙂
if we send the props.conf and transforms.conf to splunk cloud team they will configure it on indexers, my doubt her is whether the licence usage will be calculated after filtering or before filtering?
I have put some filtering using props and transforms on HF before sending the data to cloud, will it work fine when i change it to slave or free license..?
For a heavy forwarder (HF), you should set up one of the following options:
1) Make the HF a slave of a license master. This will give the HF all of the enterprise capabilities - and the HF will consume no license, as long as it does not index data.
2) Install the forwarder license. This will give the HF many enterprise capabilities, but not all. The HF will be able to parse and forward data. However, it will not be permitted to index and it will not be able to act as a deployment server (as an example). This is the option I would usually choose. (Note that the Universal Forwarder has the forwarder license pre-installed.)
I strongly discourage using either the trial license or the free license on a production forwarder.