Getting Data In

Should heavy forwarders have the same apps installed on them that are installed on the Splunk enterprise receiver?

Bill_B
Communicator

Hi. I am working on a Splunk deployment that involves a Splunk enterprise receiver at the data center and heavy forwarders at the branch offices. Do the heavy forwarders need to have the same apps installed on them as the Splunk receiver?

Thanks.

0 Karma
1 Solution

grijhwani
Motivator

This is not a straight yes/no question. It depends on what the apps are configured for. If they include transforms and filters, then possibly yes. The "receiver" as you call it does the grunt-work most of the time. But when you have a heavy forwarder in the mix, then presumably that is for a reason, and it is part-cooking the data stream it handles.

View solution in original post

grijhwani
Motivator

This is not a straight yes/no question. It depends on what the apps are configured for. If they include transforms and filters, then possibly yes. The "receiver" as you call it does the grunt-work most of the time. But when you have a heavy forwarder in the mix, then presumably that is for a reason, and it is part-cooking the data stream it handles.

Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...