Getting Data In

what is Index , search and Heavy forwarder and how they are related each other please i need help

sujeet11dec
New Member

I have 3 Ubuntu machine , but i dont know what index , search and heavy forwarder and how they are related to each other .

Please help me i am vary new into IT Security and i got splunk as an first project

Tags (2)
0 Karma

n00badmin
Communicator

Have you installed Splunk Enterprise on the machines?

0 Karma

n00badmin
Communicator

You simply need to install Splunk Enterprise on 3 linux machines and configure one to forward and one to be a search only.

http://docs.splunk.com/Documentation/Splunk/latest/Installation/Whatsinthismanual

0 Karma

sujeet11dec
New Member

Hi n00badmin

Please i need your small help here what need to be a machine work as index , search or heavy Forwarder as per configration wise

sujeet

0 Karma

n00badmin
Communicator

First you should do some reading. Splunk documentation is some of the best

http://docs.splunk.com/Documentation/Splunk

A heavy forwarder is a full install of splunk that forwards data to an indexer.

The indexer indexes the data into indexes searchable from the searchhead.

START HERE : http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Distributedoverview

0 Karma

sujeet11dec
New Member

Please i need brief answer

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...