Getting Data In

Should heavy forwarders have the same apps installed on them that are installed on the Splunk enterprise receiver?

Bill_B
Communicator

Hi. I am working on a Splunk deployment that involves a Splunk enterprise receiver at the data center and heavy forwarders at the branch offices. Do the heavy forwarders need to have the same apps installed on them as the Splunk receiver?

Thanks.

0 Karma
1 Solution

grijhwani
Motivator

This is not a straight yes/no question. It depends on what the apps are configured for. If they include transforms and filters, then possibly yes. The "receiver" as you call it does the grunt-work most of the time. But when you have a heavy forwarder in the mix, then presumably that is for a reason, and it is part-cooking the data stream it handles.

View solution in original post

grijhwani
Motivator

This is not a straight yes/no question. It depends on what the apps are configured for. If they include transforms and filters, then possibly yes. The "receiver" as you call it does the grunt-work most of the time. But when you have a heavy forwarder in the mix, then presumably that is for a reason, and it is part-cooking the data stream it handles.

Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...