Getting Data In

universal forwarder

sarah89
Path Finder

hello

can we install the splunk instance as an indexer and universal forwarder in the same machine and try to forward data beteween them

Tags (1)
0 Karma
1 Solution

MarioM
Motivator

why would you want to do that as an indexer can collect data directly too (and even forward data to another indexer or 3rd party ie:syslog-ng)?

If you still want to do that you will need to change splunkd listening port 8089 on one of them.

View solution in original post

0 Karma

MarioM
Motivator

why would you want to do that as an indexer can collect data directly too (and even forward data to another indexer or 3rd party ie:syslog-ng)?

If you still want to do that you will need to change splunkd listening port 8089 on one of them.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Yes, in normal circumstances really no need to do this since the indexer can directly do everything the UF can do. However, this can be useful for testing purposes, or for some more complex load-balancing or failover purposes.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...