Getting Data In

Heavy Forwarders as an intermediary Layer Using indexer discovery

ChrisLH
Explorer

Hey,

we are using multiple HF to collect data from different groups of UF before sending it to a multi site Indexer Cluster. I want to activate indexer discovery to make it easier to size/change the Indexer Cluster. I know the process only from UF and am wondering if it is the same for HF. Do I just change the outputs.conf on the HF similar to the changes I do on the UF when activating Indexer Discovery?

I tried it in my test environment and have problems to get it working. Should it work that way ? I just want to check with you If I am having the right idea or if there is something fundamentally wrong with my understanding of Indexer Discovery.

Thanks, Chris

0 Karma
1 Solution

ChrisLH
Explorer

Fixed, It's working now.

View solution in original post

0 Karma

ChrisLH
Explorer

Fixed, It's working now.

0 Karma

somesoni2
Revered Legend

I don't see a reason why it won't work from Intermediate Heavy forwarder (assuming your UFs are sending data to these HFs). What kind of issues you're seeing when you configured your HF for Indexer discovery?

0 Karma

ChrisLH
Explorer

Hey, thanks for the reply. I got it working, somehow I repeatedly managed to change my config in the wrong app folder before pushing the intended app to the HF. Was getting crazy and wanted to check if the concept of what I was trying to achieve is plausible before digging deeper. Sometimes a night of sleep provides a new perspective (changed wrong config) on a problem.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...