Getting Data In

Question on heavy forwarder

splunker12er
Motivator

Heavy forwarders can index and forward the data to Splunk indexers. In this case do we need any local configurations (props,transforms,etc) at indexers side., since we need to set all the local configurations at heavy forwarder itself. What is the format of the indexed data from the heavy forwarder to indexer ?

Does the format of the indexed data in heavy forwarder & indexer are similar ?

Can i point a universal forwarder to Splunk heavy forwarder ?

Tags (1)
0 Karma

lguinn2
Legend

The format between the heavy forwarder and indexer is "cooked" - which means the data after parsing, along with the metadata. All the parsing configurations need to be set on the heavy forwarder (props.conf, transforms.conf). However, some settings may need to be on the indexer or search head. While you can figure out the differences, I think it is just easier to have a duplicate of the props.conf and transforms.conf in both places - Splunk will ignore any settings it doesn't need.

If you are keeping a local index on the heavy forwarders, then it isn't really just a forwarder is it! Regardless of where you index the data, the format will be the same. BTW, if your heavy forward is set to "index and forward", it will need a Splunk license.

Yes, you can point a universal forwarder to a heavy forwarder. It works great. Just be sure to set up the receiving port on the heavy forwarder, and well as outputs.conf on the universal forwarder.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...