Getting Data In

How to configure Splunk Heavy Forwarder and Splunk Searchhead on the same machine?

sarvesh_11
Communicator

Hi @gcusello (tagging u because i have seen many of your answers in this context 🙂 ) ,
Is it possible to configure Splunk Heavy Forwarder and Search head on the same machine?
As our indexer is on Splunk Cloud, for the data formatting, to work on props.conf we need a heavy forwarder in between UF and Indexer. Also, i am restricted for the count of machine i can engage.
What i am left with is, to configure HF and SH on same machine.

TIA

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi sarvesh_11,
Heavy Forwarder is a full Splunk installation where all logs are redirected to Indexers; it's also possible to locally index data but this shouldn't be your requirement!
Search Head is a full Splunk installation used for User Interface and usually, when you configure a SH, it's a good practice to send SH's logs to the indexers, in other words to use it as an HF.
So you can use a server for both your roles.

The question is: why to do this?
In Splunk Cloud you have both Indexers and Search Heads, not only Indexers.
The advantage to have Splunk Cloud is that all the Splunk infrastructure is accessible in cloud.
In addition, in Splunk Cloud you access only Search Heads, you cannot access Indexers! so there's no sense to have a local SH.

Anyway, if you want to do this, remember to correctly dimention your server for both the roles (in terms of CPUs and RAM).

Bye.
Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi sarvesh_11,
Heavy Forwarder is a full Splunk installation where all logs are redirected to Indexers; it's also possible to locally index data but this shouldn't be your requirement!
Search Head is a full Splunk installation used for User Interface and usually, when you configure a SH, it's a good practice to send SH's logs to the indexers, in other words to use it as an HF.
So you can use a server for both your roles.

The question is: why to do this?
In Splunk Cloud you have both Indexers and Search Heads, not only Indexers.
The advantage to have Splunk Cloud is that all the Splunk infrastructure is accessible in cloud.
In addition, in Splunk Cloud you access only Search Heads, you cannot access Indexers! so there's no sense to have a local SH.

Anyway, if you want to do this, remember to correctly dimention your server for both the roles (in terms of CPUs and RAM).

Bye.
Giuseppe

o_calmels
Communicator

Hi sarvesh_11,

I can see Two ways:
1 - transform your UF in HF
2 - install splunk enterprise on the "SH" server, then configure inputs. conf, outputs.conf and TA if necessary as you should do it on the HF.

A single instance can have multiple roles.

Cheers.

Olivier.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...