Getting Data In

Splunk Heavy Forwarder

Vladimir
Path Finder

Hi,

Will Splunk support heavy forwarder in future or it's going to be decommitted?
I'm asking because there are only links to Splunk and SplunkUniversalForwarder in download section.

Thanks,
Vladimir

1 Solution

OL
Communicator

Splunk UF is way lighter and the only job it is (almost!) doing is forwarding the collected data the Splunk instance. There is no processing here. That's why it is less resource demanding.

Moreover, on the security point of view, the UF doesn't have a web UI and therefore you cannot unable it. This can be important in some cases.

Hope it helps.

Regards,
OL

View solution in original post

Vladimir
Path Finder

Thanks very much to all!

0 Karma

OL
Communicator

Splunk UF is way lighter and the only job it is (almost!) doing is forwarding the collected data the Splunk instance. There is no processing here. That's why it is less resource demanding.

Moreover, on the security point of view, the UF doesn't have a web UI and therefore you cannot unable it. This can be important in some cases.

Hope it helps.

Regards,
OL

Vladimir
Path Finder

So, in this case there is no advantages in using Splunk+SplunkUniversalForwarder instead of Splunk with configuring forwarding, right?

0 Karma

sseekamp
Explorer

Vladimir,

The heavy forwarder is just the full install of Splunk. There is no separate download for it.

Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...