Getting Data In

how to use Universal Forwarder as an receiver and start loadbalancing

rechteklebe
Path Finder

Hi,

i would like to use one of my universal forwarder as a second indexer. Please help me how to do it.

In the second step i would like to configure that all forwarders send data to both indexer in a loadbalancer mode.

Can you help me please?

thanks

0 Karma

kristian_kolb
Ultra Champion

You cannot use the Universal Forwarder to index events. In order to have an extra indexer, you need to install a the full Splunk product.

/K

Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...