Getting Data In

Should heavy forwarders have the same apps installed on them that are installed on the Splunk enterprise receiver?

Bill_B
Communicator

Hi. I am working on a Splunk deployment that involves a Splunk enterprise receiver at the data center and heavy forwarders at the branch offices. Do the heavy forwarders need to have the same apps installed on them as the Splunk receiver?

Thanks.

0 Karma
1 Solution

grijhwani
Motivator

This is not a straight yes/no question. It depends on what the apps are configured for. If they include transforms and filters, then possibly yes. The "receiver" as you call it does the grunt-work most of the time. But when you have a heavy forwarder in the mix, then presumably that is for a reason, and it is part-cooking the data stream it handles.

View solution in original post

grijhwani
Motivator

This is not a straight yes/no question. It depends on what the apps are configured for. If they include transforms and filters, then possibly yes. The "receiver" as you call it does the grunt-work most of the time. But when you have a heavy forwarder in the mix, then presumably that is for a reason, and it is part-cooking the data stream it handles.

Get Updates on the Splunk Community!

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...