Getting Data In

Does TRANSFORMS applies on Heavy Forwarder or on Indexer?

VatsalJagani
Super Champion

Let me know the correct scenario for heavy forwarder if I'm using only forwarding and not indexing and forwarding?

  1. Heavy forwarder applies the TRANSFORMS (including nullQueue and other) and it sends the transformed data to indexer.
  2. Heavy forwarder sends the _raw data only to indexer and TRANSFORM will only happens if I'm using IndexAndForward.

In case of the first scenario is correct, will the TRANSFORMS applies on indexer as well?

0 Karma
1 Solution

woodcock
Esteemed Legend

Any TRANSFORMS- setting applies to the first full instance of splunk who handles the event. So if you are using HFs, it will be the HFs, if not, it will be the Indexers.

View solution in original post

woodcock
Esteemed Legend

Any TRANSFORMS- setting applies to the first full instance of splunk who handles the event. So if you are using HFs, it will be the HFs, if not, it will be the Indexers.

VatsalJagani
Super Champion

Thanks @woodcock for the answer that make sense. I've also recently verified this by small POC.

Do all parsing happens on HF of there are some config that specifically handles on indexer?

0 Karma

woodcock
Esteemed Legend

All index-time things will happen on the HF.

0 Karma
Get Updates on the Splunk Community!

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...