Getting Data In

Forward data without effecting ingest volume

dloszews
Explorer

Hello,

We have one universal forwarder, and two cloud instances.   Currently I have all data going to 1 indexer, I've been attempting to determine the most efficient way to parse and route the data so that it will go to the correct indexer/splunk instance without effecting ingest volume.   If I ingest everything into the "primary" indexer can I just parse and route that raw data to the "secondary" indexer without effecting ingest volume on the "primary"? 

I was originally going to use a heavy forwarder for the parsing and routing but sounds like that may be more network IO intensive.  

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @dloszews,

if you index a log before in an Indexer and then in another one (also in Cloud), you ingest this log twice and pay twice the license!

For this reason the correct option is to use an Heavy Forwarder that has all the features of an Indexer but it doesn't index data so you don't pay it twice.

I don't understand what you mean that using an HF is more Network intensive, it's the same thing because you're sending the same data from primary (Indexer or HF) to the Cloud.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mile High Learning with Splunk University, Denver, Colorado

If Denver is known for its mile-high elevation, Splunk University is about to raise the bar on technical ...

IT Service Intelligence 5.0 Series: Your Guide to the June Launch

We are excited to announce the June release of Splunk IT Service Intelligence (ITSI) 5.0. This update ...

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...