Getting Data In

Should heavy forwarders have the same apps installed on them that are installed on the Splunk enterprise receiver?

Bill_B
Communicator

Hi. I am working on a Splunk deployment that involves a Splunk enterprise receiver at the data center and heavy forwarders at the branch offices. Do the heavy forwarders need to have the same apps installed on them as the Splunk receiver?

Thanks.

0 Karma
1 Solution

grijhwani
Motivator

This is not a straight yes/no question. It depends on what the apps are configured for. If they include transforms and filters, then possibly yes. The "receiver" as you call it does the grunt-work most of the time. But when you have a heavy forwarder in the mix, then presumably that is for a reason, and it is part-cooking the data stream it handles.

View solution in original post

grijhwani
Motivator

This is not a straight yes/no question. It depends on what the apps are configured for. If they include transforms and filters, then possibly yes. The "receiver" as you call it does the grunt-work most of the time. But when you have a heavy forwarder in the mix, then presumably that is for a reason, and it is part-cooking the data stream it handles.

Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...