Getting Data In

When setting up a heavy forwarder, do I need to create an index locally as I do in my indexer cluster?

brent_weaver
Builder

When setting up a Heavy forwarder, do I need to have the index created locally as I do in my indexer cluster? So I am setting up Splunk DB Connect and McAfee and have configured the Splunk server to be a HWP. I am testing writing to an index called bitbucket. In order for this to work, do I need to have a local index called bitbucket as I do in my indexer cluster? I have configured it to not keep a local copy.

Thanks!

0 Karma
1 Solution

sk314
Builder

As long as the index exists on the indexer - you don't have to create it on the heavy forwarder. However, there is a small quirk. If you are setting up data inputs using SplunkWeb on the heavyforwarder, It doesn't have access to list of indexes on the indexers. In such a scenario, you may need to create an index just so you could use splunkweb. However, in my opinion it is an ugly hack.

View solution in original post

sk314
Builder

As long as the index exists on the indexer - you don't have to create it on the heavy forwarder. However, there is a small quirk. If you are setting up data inputs using SplunkWeb on the heavyforwarder, It doesn't have access to list of indexes on the indexers. In such a scenario, you may need to create an index just so you could use splunkweb. However, in my opinion it is an ugly hack.

somesoni2
Revered Legend

Agree. If you're going to setup your data input directly in conf files (inputs.conf), then you don't need local indexes (indexes.conf) on HF. For any other method of creating data input, using Splunk CLI OR Splunk Web, you'd need indexes.conf available on HF (same as what you've on indexer cluster, for CLI it will give you warning for non-existent index but may work, never tried).

0 Karma

saurabh_tek11
Communicator

Thanks for your answer.

0 Karma

brent_weaver
Builder

Thank you all for the help... What you guys are saying makes total sense.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...