Splunk Enterprise

Splunk forwarder in regulated environment

FGo
Engager

Dear Splunk Experts,

We plan using your product in a regulated environment, having a question on the (heavy) forwarder.
In such area, installation of a product requires proving the absence of retroactive effects on the base system.
1) Your product offers remote access to the base system, offering great convenience, but thereby potentially modifying the base system, offending the above requirement. Is there a reloably means to prevent a forwarder from offering this feature?
2) Can you give upper limits for memory and CPU resource usage? Again, this is required for a tool that aims at being suitable for installation in the regulated environment we find us in.
3) Do you keep service records for products with a given version, so that one could take credit from showing successful use of the product in a significant amount of cases? This typically includes track records on known issues.

Thanks in advance for your effort,
best regards,
Frank

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

These questions probably should be directed to your Splunk sales team.  This is a community forum and we members of the community can't answer all of these questions, especially #3.

Regarding question #1, the only part of the file system a forwarder writes to is the directory in which Splunk runs (/opt/splunk by default).

How much system resources a heavy forwarder (HF) uses depends on how the HF is used, but usually it's relatively small.  Actions like transforming or queuing can cause more resources to be used.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

FGo
Engager

Thanks for your answer, so I will look forward contacting sales!

richgalloway
SplunkTrust
SplunkTrust

These questions probably should be directed to your Splunk sales team.  This is a community forum and we members of the community can't answer all of these questions, especially #3.

Regarding question #1, the only part of the file system a forwarder writes to is the directory in which Splunk runs (/opt/splunk by default).

How much system resources a heavy forwarder (HF) uses depends on how the HF is used, but usually it's relatively small.  Actions like transforming or queuing can cause more resources to be used.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...