Getting Data In

Using a Splunk Forwarder versus adding the data from a network drive

paduka
Path Finder

Hi,

I am facing some performance challenges and hence wanted to get clarification on a few things. I have data sitting on two drives. I am indexing this data on Splunk. I have currently added these two mount drives as network drive on my computer and added the inputs locally on the indexer.

However, another solution could be to forward the data from these two locations, using an universal forwarder, to the indexer machine.

Since, our system performance is really slow with a distributed setup of an indexer and a searchhead. I want to know if using forwarders has a performance advantage over adding data by adding the network drives.

Thanks!

0 Karma
1 Solution

TStrauch
Communicator

Hi,

simple answer. No.

Until there are no restrictions in your networksegements and you can add the mount the drives without problems you can just do that. Using a forwarder at this point will not give you any performance advantages.

Of course there are advantages of using forwarders espacially on big infrastructures, but thats not a part of the answer to your question.

Kind regards

View solution in original post

TStrauch
Communicator

Hi,

simple answer. No.

Until there are no restrictions in your networksegements and you can add the mount the drives without problems you can just do that. Using a forwarder at this point will not give you any performance advantages.

Of course there are advantages of using forwarders espacially on big infrastructures, but thats not a part of the answer to your question.

Kind regards

gcusello
SplunkTrust
SplunkTrust

Sure, because Splunk Universal forwarder optimize and compress data before send them to the Indexer.
In addition, you can configure a network bandwidth value so you don't fill your network.
see:
- http://blogs.splunk.com/2011/10/24/choosing-a-forwarder-or-not/
- http://docs.splunk.com/Documentation/Splunk/6.4.2/Indexer/useforwarders

Bye.
Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

if you're satisfied of the answer, please, accept the answer.
Bye.
Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...