Getting Data In

do i need a different license to install splunkforwarder?

just4me
Engager

do i need a different license to install splunkforwarder if i already have an enterprise license for splunk? also installing splunk forwarder seems like a separate instance that i have to install on my server? is that correct

Tags (2)

piebob
Splunk Employee
Splunk Employee

documentation for forwarder licenses is here:
http://docs.splunk.com/Documentation/Splunk/5.0/Admin/TypesofSplunklicenses#Forwarder_license

the tl;ldr answer is: no. if you're installing a universal forwarder, it will not be indexing any data, so you don't need to install a separate license on it (it comes with its own separate license pre-installed and enabled).

the universal forwarder is a separate package and should be installed as needed on the system(s) from which you want to forward data. review this topic and others about forwarding:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Aboutforwardingandreceivingdata

piebob
Splunk Employee
Splunk Employee

if you are going to be indexing data on that forwarder, you do not need a separate license, but you will need to add it as a slave to your license master and give it access to the enterprise license stack per the docs link i provided above.

just4me
Engager

i'm planning on installing heavy fowarder as we need the indexing feature of the heavy indexer.
do i need another liecense in this case?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...