Getting Data In

How much license do I need if I'm using a heavy forwarder to send data only to a syslog server, not to an indexer?

ibatalla
New Member

Hi guys,

I'm using a heavy forwarder to send data to a syslog server. If I don't send data to an indexer and only use the heavy forwarder to send to syslog, what is the license that I need?

thanks a lot.

0 Karma
1 Solution

satishsdange
Builder

There are 4 stages of Splunking -
1. Inputs - data is gathered from sources (files, network, servers, applications etc)
2. Parsing - data is analyzed, broken into events, metadata (such as timestamp, source type etc) is assigned, and (optional) raw data can be filtered or modified

3. Indexing - the data is written to permanent storage in Splunk
4. Searching - searches are run on the data stored in Splunk

Whatever volume of data is written to disk in stage 3, you should purchase that much license.

View solution in original post

satishsdange
Builder

There are 4 stages of Splunking -
1. Inputs - data is gathered from sources (files, network, servers, applications etc)
2. Parsing - data is analyzed, broken into events, metadata (such as timestamp, source type etc) is assigned, and (optional) raw data can be filtered or modified

3. Indexing - the data is written to permanent storage in Splunk
4. Searching - searches are run on the data stored in Splunk

Whatever volume of data is written to disk in stage 3, you should purchase that much license.

Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...