Hi,
I am setting up Splunk Arcitecture.To start, After installing the tar file how do we configure that tar to act as Heavy Forwader?
what is the configuration file which make it as HF?
Any suggestion or doc please?
Heavy Forwareder, Search Head,Indexer,license Master, Deployment server, these are different role for splunk, the installation is no different among them. The only difference is how you do the configuration. You can use one instance to play all the role in one server., OR deploy each role in different servers, that depend on the scaling of your deployment.
https://docs.splunk.com/Documentation/Splunk/8.1.3/Deploy/Distributedoverview
What configuration gets created when we run the below command?
splunk enable app SplunkForwarder -auth <username>:<password>
Hi @Ashwini008
this comand is for the uf.
Please read this documentation to understand the difference from UF to HF.
https://www.splunk.com/en_us/blog/tips-and-tricks/universal-or-heavy-that-is-the-question.html
Karma given or solution confirmation is appreciated
Hi @Ashwini008 ,
the installation of splunk ROLE is the same, for the HF you need to set up the forwarder license.
Please check the documentation for the roles
https://docs.splunk.com/Documentation/Splunk/8.1.3/Updating/Deploymentserverarchitecture