Getting Data In

How to configure Heavy Forwarder with License Slave in Splunk Cloud

markuxProof
Path Finder

Greetings,

Is it possible to set up a heavy forwarder as a license slave in a Spluk Cloud architecture?

prakash007
Builder

If you don't index the data locally on a HF....you can use a forwarder(1MB) license

https://answers.splunk.com/answers/395082/do-we-need-a-license-for-heavy-forwarder.html

markuxProof
Path Finder

tks, mcnamara.

But in my case, I need an HF because I'm using the SA-LDAPSearch add-on that I can not install on the Universal Forwarder.

I need to access the license master in the Splunk Cloud, but I do not know if this is possible.

0 Karma

prakash007
Builder

If I am not wrong, you can use a forwarder license on the HF and install the add-ons, as it does have the advancing parsing capabilities...

http://docs.splunk.com/Documentation/SA-LdapSearch/2.1.4/User/Platformandhardwarerequirements

0 Karma

markuxProof
Path Finder

But does HF continue to run ldap queries?

If HF does not lose the ability to run LDAP queries, I can resolve the problem.

0 Karma

Esky73
Builder

Splunk can supply a 0 byte splunk license for your HF and you should still be able to use all your apps as designed as long as no indexing is configured locally.

0 Karma

markuxProof
Path Finder

There was a question: Do LDAP queries performed by the SA-LDAPSearch add-on continue to run on a heavy forwarder using the Forwarder license?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...