Getting Data In

Does data indexed and forwarded from a heavy forwarder count against the Splunk data license?

mookiie2005
Communicator

We have a Heavy forwarder load balancing data feeds from a TCP/UDP feeds to the two indexers we are using. My question is does the data indexed and then forwarded from the heavy forwarder to either indexer count against the Splunk license? This would basically charge the customer twice to index the same data. Once at the heavy forwarder and than again at the indexers. Would this change if the IndexandForward attribute was set to false?

1 Solution

kristian_kolb
Ultra Champion

Yes. A heavy forwarder is essentially an indexer, where indexing has been turned off. Turning it back on, like with indexAndForward, will require a license in order to make the events searchable on that machine.

As for charging for indexing the same data twice, that used to be one of the ways to make a Splunk installation more HA/DR-like, and I believe that you could get some sort of license discount for those types of scenarios. Since version 5, there is index replication to cater for that need (which lets your indexers make copies already indexed data at no extra cost, apart from the extra storage required).

Setting indexAndForward=false would let your Heavy Forwarder act as just that.

Hope this clarifies things a bit,

K

View solution in original post

kristian_kolb
Ultra Champion

Yes. A heavy forwarder is essentially an indexer, where indexing has been turned off. Turning it back on, like with indexAndForward, will require a license in order to make the events searchable on that machine.

As for charging for indexing the same data twice, that used to be one of the ways to make a Splunk installation more HA/DR-like, and I believe that you could get some sort of license discount for those types of scenarios. Since version 5, there is index replication to cater for that need (which lets your indexers make copies already indexed data at no extra cost, apart from the extra storage required).

Setting indexAndForward=false would let your Heavy Forwarder act as just that.

Hope this clarifies things a bit,

K

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...