Getting Data In

Question on heavy forwarder

splunker12er
Motivator

Heavy forwarders can index and forward the data to Splunk indexers. In this case do we need any local configurations (props,transforms,etc) at indexers side., since we need to set all the local configurations at heavy forwarder itself. What is the format of the indexed data from the heavy forwarder to indexer ?

Does the format of the indexed data in heavy forwarder & indexer are similar ?

Can i point a universal forwarder to Splunk heavy forwarder ?

Tags (1)
0 Karma

lguinn2
Legend

The format between the heavy forwarder and indexer is "cooked" - which means the data after parsing, along with the metadata. All the parsing configurations need to be set on the heavy forwarder (props.conf, transforms.conf). However, some settings may need to be on the indexer or search head. While you can figure out the differences, I think it is just easier to have a duplicate of the props.conf and transforms.conf in both places - Splunk will ignore any settings it doesn't need.

If you are keeping a local index on the heavy forwarders, then it isn't really just a forwarder is it! Regardless of where you index the data, the format will be the same. BTW, if your heavy forward is set to "index and forward", it will need a Splunk license.

Yes, you can point a universal forwarder to a heavy forwarder. It works great. Just be sure to set up the receiving port on the heavy forwarder, and well as outputs.conf on the universal forwarder.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

From Raw Data to Executive-Ready Stories, Faster

Build Data Stories for Every Audience  A dashboard is rarely just a dashboard. It might be the view an ...

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...