Installation

How to Minimize Light Forwarder Footprint?

mzorzi
Splunk Employee
Splunk Employee

I'm looking for a way to create a minimal light forwarder installation. What can I remove from the standard Splunk deployment to drastically reduce the disk space? Since all it does it's just forwarding data to the Indexer, I don't understand why the Light Forwarder installation has to be as large as the Indexer installation.

balbano
Contributor

@CerielTjuh:

which indexes are ok to delete? Just curious as I am also trying to setup a very minimal installation of Splunk LF as one of my legacy servers CPU and Memory is going nuts...

Let me know more details. Thanks I appreciate the help.

Brian

CerielTjuh
Path Finder

Hi mzorzi,

I reduced my footprint by deleting the demo indexes on the forwarders, limiting the log size and log indexes and removing some of the apps, (gettingsstarted, sample app).

  • I deleted the indexes trough the web interface.
  • Log files i limited using the script below

appender.A1=RollingFileAppender
appender.A1.fileName=${SPLUNK_HOME}/var/log/splunk/splunkd.log
appender.A1.maxFileSize=50000000 (used to be 25 MB)
appender.A1.maxBackupIndex=1 (used to be 5)
appender.A1.layout=PatternLayout
appender.A1.layout.ConversionPattern=%d{%m-%d-%Y %H:%M:%S.%l} %-5p %c - %m%n

Log Files Splunk Documentation

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...