Getting Data In

Using a Splunk Forwarder versus adding the data from a network drive

paduka
Path Finder

Hi,

I am facing some performance challenges and hence wanted to get clarification on a few things. I have data sitting on two drives. I am indexing this data on Splunk. I have currently added these two mount drives as network drive on my computer and added the inputs locally on the indexer.

However, another solution could be to forward the data from these two locations, using an universal forwarder, to the indexer machine.

Since, our system performance is really slow with a distributed setup of an indexer and a searchhead. I want to know if using forwarders has a performance advantage over adding data by adding the network drives.

Thanks!

0 Karma
1 Solution

TStrauch
Communicator

Hi,

simple answer. No.

Until there are no restrictions in your networksegements and you can add the mount the drives without problems you can just do that. Using a forwarder at this point will not give you any performance advantages.

Of course there are advantages of using forwarders espacially on big infrastructures, but thats not a part of the answer to your question.

Kind regards

View solution in original post

TStrauch
Communicator

Hi,

simple answer. No.

Until there are no restrictions in your networksegements and you can add the mount the drives without problems you can just do that. Using a forwarder at this point will not give you any performance advantages.

Of course there are advantages of using forwarders espacially on big infrastructures, but thats not a part of the answer to your question.

Kind regards

gcusello
SplunkTrust
SplunkTrust

Sure, because Splunk Universal forwarder optimize and compress data before send them to the Indexer.
In addition, you can configure a network bandwidth value so you don't fill your network.
see:
- http://blogs.splunk.com/2011/10/24/choosing-a-forwarder-or-not/
- http://docs.splunk.com/Documentation/Splunk/6.4.2/Indexer/useforwarders

Bye.
Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

if you're satisfied of the answer, please, accept the answer.
Bye.
Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...