Getting Data In

When setting up a heavy forwarder, do I need to create an index locally as I do in my indexer cluster?

brent_weaver
Builder

When setting up a Heavy forwarder, do I need to have the index created locally as I do in my indexer cluster? So I am setting up Splunk DB Connect and McAfee and have configured the Splunk server to be a HWP. I am testing writing to an index called bitbucket. In order for this to work, do I need to have a local index called bitbucket as I do in my indexer cluster? I have configured it to not keep a local copy.

Thanks!

0 Karma
1 Solution

sk314
Builder

As long as the index exists on the indexer - you don't have to create it on the heavy forwarder. However, there is a small quirk. If you are setting up data inputs using SplunkWeb on the heavyforwarder, It doesn't have access to list of indexes on the indexers. In such a scenario, you may need to create an index just so you could use splunkweb. However, in my opinion it is an ugly hack.

View solution in original post

sk314
Builder

As long as the index exists on the indexer - you don't have to create it on the heavy forwarder. However, there is a small quirk. If you are setting up data inputs using SplunkWeb on the heavyforwarder, It doesn't have access to list of indexes on the indexers. In such a scenario, you may need to create an index just so you could use splunkweb. However, in my opinion it is an ugly hack.

somesoni2
Revered Legend

Agree. If you're going to setup your data input directly in conf files (inputs.conf), then you don't need local indexes (indexes.conf) on HF. For any other method of creating data input, using Splunk CLI OR Splunk Web, you'd need indexes.conf available on HF (same as what you've on indexer cluster, for CLI it will give you warning for non-existent index but may work, never tried).

0 Karma

saurabh_tek11
Communicator

Thanks for your answer.

0 Karma

brent_weaver
Builder

Thank you all for the help... What you guys are saying makes total sense.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...