Getting Data In

Why do we install apps on a Heavy forwarder through a deployment server?

riqbal
Communicator

Hi everyone,

I am confused about deployment server function. can anyone elaborate it in simple words,
secondly why we need to install apps on heavy forwarders.

0 Karma
1 Solution

ritureddy
Engager

heavy forwarder is intermediate component between universal and indexer components. its eliminate the garbage data and its do index routing, masking the data and sourcetype routing before going to indexer. for this purpose we have to use props.conf and transforms.conf files.

in transforms.conf we have to set the rules and in props.conf what is rule and to whom to apply.

,

View solution in original post

0 Karma

sc31656us
New Member

The deployment server is used to deploy configuration files (like inputs.conf or props and transforms...) / TA's / Apps to end points that have a universal forwarder on them. It allows you to push config changes to all your end points without having to do it manually one by one.

There are some apps that require the python libraries that come with a HF. This is why some apps may require the use of a Heavy Forwarder.

Types of forwarders: http://docs.splunk.com/Documentation/Splunk/7.2.0/Forwarding/Typesofforwarders

0 Karma

ritureddy
Engager

heavy forwarder is intermediate component between universal and indexer components. its eliminate the garbage data and its do index routing, masking the data and sourcetype routing before going to indexer. for this purpose we have to use props.conf and transforms.conf files.

in transforms.conf we have to set the rules and in props.conf what is rule and to whom to apply.

,

0 Karma

ddrillic
Ultra Champion

Magnificent centralized configuration mechanism ; -)

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...