Hi Team,
Could you please clarify my doubt on connectivity between Heavy forwarder and Universal Forwarder. I have 2 site, Heavy forwarder and universal forwarder on both site. Do I need to connect the heavy forwarder on X site to universal forwarder on X site only or do I need to connect HF on X site to both X and Y site UFs.
There will be connectivity between both sites. Heavy forwarder are not connected to each other. they will be pushing data to indexers which are clustered.
It depends on your circumstances and needs. Using only local HFs can be desired if you have severely limited bandwidth between sites or some data security limitation. Using all HFs on the other hand removes SPOF and allows for better workload distribution.
So there is no sigle optimal solution for all possible cases
Hi,
I want is to configure universal forwarder to send logs/data to heavy forwarders and do some filtering there, and then forward the logs to indexers from heavy weight forwarders.
Then create a normal output.conf on uf and point it to hf and on hf create input similar to indexers
[Splunktcp://: port ]
Rest of your input config
And hf is already connected to indexers so it should start sending data.
Use props on hf to filter data and a should be set.
Then create a normal output.conf on uf and point it to hf ---- both sites HF ?
x to x and y to y
for more info check this post out