Getting Data In

Why do we install apps on a Heavy forwarder through a deployment server?

riqbal
Communicator

Hi everyone,

I am confused about deployment server function. can anyone elaborate it in simple words,
secondly why we need to install apps on heavy forwarders.

0 Karma
1 Solution

ritureddy
Engager

heavy forwarder is intermediate component between universal and indexer components. its eliminate the garbage data and its do index routing, masking the data and sourcetype routing before going to indexer. for this purpose we have to use props.conf and transforms.conf files.

in transforms.conf we have to set the rules and in props.conf what is rule and to whom to apply.

,

View solution in original post

0 Karma

sc31656us
New Member

The deployment server is used to deploy configuration files (like inputs.conf or props and transforms...) / TA's / Apps to end points that have a universal forwarder on them. It allows you to push config changes to all your end points without having to do it manually one by one.

There are some apps that require the python libraries that come with a HF. This is why some apps may require the use of a Heavy Forwarder.

Types of forwarders: http://docs.splunk.com/Documentation/Splunk/7.2.0/Forwarding/Typesofforwarders

0 Karma

ritureddy
Engager

heavy forwarder is intermediate component between universal and indexer components. its eliminate the garbage data and its do index routing, masking the data and sourcetype routing before going to indexer. for this purpose we have to use props.conf and transforms.conf files.

in transforms.conf we have to set the rules and in props.conf what is rule and to whom to apply.

,

0 Karma

ddrillic
Ultra Champion

Magnificent centralized configuration mechanism ; -)

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...