- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Does Heavy forwarder forwarded events will undergo parsing on indexers
ankithreddy777
Contributor
08-23-2017
07:36 AM
my Heavy forwarder is forwarding events to Splunk indexers. Does link breaking , aggregation etc takes place on indexers again?
If not is there any way to make events to undergo parsing on indexers even though they already got parsed on Heavy Forwarders?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
s2_splunk
![Splunk Employee Splunk Employee](/html/@F88B7774A2BF2E9108D79A067A92A581/rank_icons/employee-16.png)
Splunk Employee
08-23-2017
09:05 AM
Why would you want to do that, what is your use case?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
![somesoni2 somesoni2](https://community.splunk.com/legacyfs/online/avatars/100305.jpg)
somesoni2
Revered Legend
08-23-2017
08:00 AM
Splunk doesn't reparse the data at indexer once it's already parsed (cooked) at Heavy forwarder level. You can follow configuration from following post to enable reparsing at indexer.
https://answers.splunk.com/answers/224312/hf1-hf2-indexer-how-to-route-a-set-of-data-that-ha.html
Please note that you can't enable this setting for selected data/sourcetype, so if enabled, it will reparse all data that comes in.
![](/skins/images/5D2DD17C284106BFBF80528D01D8AA1A/responsive_peak/images/icon_anonymous_message.png)