Installation

Licsencing Question Splunk Intermediate Heavy Forwarder for like 200 GB per day

haraldcgi
New Member

We would like to use the Intermediate Heavy Forwarder Licsence is free or not for like 200 gb Traffic over it).
We are thinking about implementing Splunk IHF for a customer - can you please answer this

Tags (1)
0 Karma
1 Solution

gjanders
SplunkTrust
SplunkTrust

The forwarder license has zero cost, you can forward as much as you like.

Licensing is charged for indexed data for event data and differently for metrics, for more details refer to How Splunk Enterprise licensing works

View solution in original post

0 Karma

haraldcgi
New Member

I just got maybe an somewhat unusual question: Is it possible to use the Intermediate Heavy Forwarder without the Splunk Enterprise or other parts installed ?

0 Karma

gjanders
SplunkTrust
SplunkTrust

You can use a splunk universal forwarder as an aggregation point...

A UF can receive data and forward the data. However the best practice is forwarder to indexer where possible

0 Karma

haraldcgi
New Member

Thank you for the additional info.

0 Karma

haraldcgi
New Member

Thank you for your quick answer.

0 Karma

gjanders
SplunkTrust
SplunkTrust

The forwarder license has zero cost, you can forward as much as you like.

Licensing is charged for indexed data for event data and differently for metrics, for more details refer to How Splunk Enterprise licensing works

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...