Getting Data In

How do I convert my indexer into a heavy forwarder?

New Member

Long story short, I was indexing my own data for years now and recently started forwarding up stream to another cluster. I don't need to index on my network anymore and just want to have my indexer serve as a heavy forwarder so I don't have to reconfigure 600+ endpoints. Is this feasible or will I break lots of things?


Labels (3)
0 Karma


The main difference between an indexer and a HF is the HF has an outputs.conf file.

Keep in mind that once the indexer becomes a HF any data stored on it becomes unreachable to the upstream cluster.  The HF should still be able to search it, however, but I have no experience with that setup.  It may be possible to add the HF as a search peer to the upstream cluster, but I've not tried it and don't of any possible hazards.

I also should point out that having a single intermediate forwarder (IF) can be problematic.  It will be a single point of failure that will prevent all of your data from reaching the indexer.  It can lead to an uneven distribution of events across the indexers, which will affect search performance.  A would be better to use the deployment server to push a new outputs.conf file to the UFs.

If this reply helps you, Karma would be appreciated.
0 Karma



As @richgalloway said, it quite easy to switch IDX to HF, but can you search that old data or not is interesting question. I haven't try it as usually it's much easier and cheaper (you probably have lot of disk space used in indexer which are not needed on HF and probably more resources than it's needed after switch over?) to add a new HF than convert IDX to HF. Basically just install a new instance then switch those IP's to then new one and add that old as a search peer to the new SH(s). 

Of course you can and actually should add HF to search peer to your MC to see what happening there, but add HF as "normal" search peer to SH maybe not the best option?

If you still want to convert your indexer as a HF then just add a outputs.conf which sends all events to the new indexer(s) as described here:

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...

There's No Place Like Chrome and the Splunk Platform

WATCH NOW!Malware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

Customer Experience | Join the Customer Advisory Board!

Are you ready to take your Splunk journey to the next level? 🚀 We invite you to join our elite squad ...