Getting Data In

When setting up a heavy forwarder, do I need to create an index locally as I do in my indexer cluster?

brent_weaver
Builder

When setting up a Heavy forwarder, do I need to have the index created locally as I do in my indexer cluster? So I am setting up Splunk DB Connect and McAfee and have configured the Splunk server to be a HWP. I am testing writing to an index called bitbucket. In order for this to work, do I need to have a local index called bitbucket as I do in my indexer cluster? I have configured it to not keep a local copy.

Thanks!

0 Karma
1 Solution

sk314
Builder

As long as the index exists on the indexer - you don't have to create it on the heavy forwarder. However, there is a small quirk. If you are setting up data inputs using SplunkWeb on the heavyforwarder, It doesn't have access to list of indexes on the indexers. In such a scenario, you may need to create an index just so you could use splunkweb. However, in my opinion it is an ugly hack.

View solution in original post

sk314
Builder

As long as the index exists on the indexer - you don't have to create it on the heavy forwarder. However, there is a small quirk. If you are setting up data inputs using SplunkWeb on the heavyforwarder, It doesn't have access to list of indexes on the indexers. In such a scenario, you may need to create an index just so you could use splunkweb. However, in my opinion it is an ugly hack.

somesoni2
Revered Legend

Agree. If you're going to setup your data input directly in conf files (inputs.conf), then you don't need local indexes (indexes.conf) on HF. For any other method of creating data input, using Splunk CLI OR Splunk Web, you'd need indexes.conf available on HF (same as what you've on indexer cluster, for CLI it will give you warning for non-existent index but may work, never tried).

0 Karma

saurabh_tek11
Communicator

Thanks for your answer.

0 Karma

brent_weaver
Builder

Thank you all for the help... What you guys are saying makes total sense.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...