Installation

Is there a way I can see what is using the Search Heads as forwarders?

Gregski11
Contributor

I see that in our environment some of our Search Heads are setup as forwarders and some are not, I think this environment like most grew from one server to a multiple server environment all before my time

Now we have Search Heads and dedicated Deployment servers aka Forwarders which leads me to believe we no loner need the Search Heads to forward anything, so is there a way I can see what is using the Search Heads as forwarders?

Labels (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Gregski11,

it isn't a best practice to have indexes in different locations than the Indexers, especially on Search Head!

So I should avoid this and I should send all logs to Indexers.

if one answer solves your need, please accept one answer for the other people of Community or tell me how I can help you.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @Gregski11,

it's a best practice that all Splunk systems send theit internal logs to the Indexers, so, all of them (obviously with the exception of Indexers themselves).

To configure Search Heads or the other Splunk instances (Deployment Server, Deployer, etc...) you have to go in [Settings > Forwarding and Receiving > Forwarding] and configure the destination Indexers.

You can have confirmation of correct forwarding configuration with a simple search on _internal index or (better) using the Monitoring Console App.

Ciao.

Giuseppe

Gregski11
Contributor

thank you so much Giuseppe

a quick follow up question, I get what you are saying, but that is the case if something some app is actually pointing to an Index on that Search Head? so the Search Head will say oh no you don't you can't store your data here, off you go to a proper Indexer?

In other words, in a perfect world with every app pointing to an index on one of our many many Indexers, we would not have to have our Search Heads set up as forwarders to our Indexers? 

Oh wait I think I may have just answered my own question, I think we still do, just so that the Search Heads can ingest their own internal Indexer data into the Index cluster so that it all lives in one bucket!

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Gregski11,

it isn't a best practice to have indexes in different locations than the Indexers, especially on Search Head!

So I should avoid this and I should send all logs to Indexers.

if one answer solves your need, please accept one answer for the other people of Community or tell me how I can help you.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...