Getting Data In

Using a Splunk Forwarder versus adding the data from a network drive

paduka
Path Finder

Hi,

I am facing some performance challenges and hence wanted to get clarification on a few things. I have data sitting on two drives. I am indexing this data on Splunk. I have currently added these two mount drives as network drive on my computer and added the inputs locally on the indexer.

However, another solution could be to forward the data from these two locations, using an universal forwarder, to the indexer machine.

Since, our system performance is really slow with a distributed setup of an indexer and a searchhead. I want to know if using forwarders has a performance advantage over adding data by adding the network drives.

Thanks!

0 Karma
1 Solution

TStrauch
Communicator

Hi,

simple answer. No.

Until there are no restrictions in your networksegements and you can add the mount the drives without problems you can just do that. Using a forwarder at this point will not give you any performance advantages.

Of course there are advantages of using forwarders espacially on big infrastructures, but thats not a part of the answer to your question.

Kind regards

View solution in original post

TStrauch
Communicator

Hi,

simple answer. No.

Until there are no restrictions in your networksegements and you can add the mount the drives without problems you can just do that. Using a forwarder at this point will not give you any performance advantages.

Of course there are advantages of using forwarders espacially on big infrastructures, but thats not a part of the answer to your question.

Kind regards

gcusello
SplunkTrust
SplunkTrust

Sure, because Splunk Universal forwarder optimize and compress data before send them to the Indexer.
In addition, you can configure a network bandwidth value so you don't fill your network.
see:
- http://blogs.splunk.com/2011/10/24/choosing-a-forwarder-or-not/
- http://docs.splunk.com/Documentation/Splunk/6.4.2/Indexer/useforwarders

Bye.
Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

if you're satisfied of the answer, please, accept the answer.
Bye.
Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...