Getting Data In

What are the capabilities of the Splunk Forwarder license?

FritzWittwer_ol
Contributor

We are running heavy forwarders to accept events from a number of universal forwarders, do some transforms and filtering with props and transforms, and then send them to our indexers.

We'd like to use the forwarder license on them, so we don't have to enable a connection to our license master. What capabilities are enabled with this license? Or more specific, are the functions of the parsing, merging and typing pipelines, according to HowIndexingWorks, available with the forwarding license?

0 Karma

vishaltaneja070
Motivator

Hello @FritzWittwer,

Forwarder license is already included in every splunk package which only allows data forwarding nothing else not even parsing.
The Forwarder license allows forwarding of unlimited data. Unlike a Free license, it enables authentication.

The Forwarder license is available only for instances that simply forward data. It is not valid for use on instances that also perform additional functions, such as indexing.

Forwarder licenses are included with Splunk. You do not need to purchase them separately.

There are several types of forwarders:

The universal forwarder has the Forwarder license applied automatically.
The light forwarder uses the Forwarder license, but you must manually enable it by changing to the Forwarder license group.
The heavy forwarder must also be manually converted to the Forwarder license group. If the heavy forwarder will also be performing indexing, the forwarder must instead have access to an Enterprise license.

Please see the below link:
https://docs.splunk.com/Documentation/Splunk/7.2.3/Admin/TypesofSplunklicenses

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...