Splunk Search

How to split cooking data and routing between two (or more) forwarders?

MMCC
Path Finder

Hi all,

I have already read several interesting questions regarding this topic. I'd like to verify which approach is better.

This wiki entry really helps: https://wiki.splunk.com/Community:HowIndexingWorks
(topic 4. Detail Diagram - UF/LWF to Indexer)

Goal: Routing of the data to the indexer layer / specific indexer (Indexer S)
Issue: First forwarder can't communicate with the indexer directly (e.g. security etc.)

I see now two options.

Option A:
I perform nothing with the data on the first (or more) forwarders until I reach the forwarder connected to the IX layer.
-> so to speak pass through the data "raw"

Option B:
I cook the data on the first forwarder and on following forwarders I configure the next "queue" to be "typingQueue".
Which should enable the routing capability of each following forwarder in the line.

See following picture below for details:
alt text

Which approach seems more feasible?

Thank you in advance for any hints and remarks.

Ps. Good input was found here:
https://answers.splunk.com/answers/463643/does-cooked-data-from-a-hf-forwarder-automatically.html

https://answers.splunk.com/answers/97918/reparsing-cooked-data-coming-from-a-heavy-forwarder-possibl...

https://answers.splunk.com/answers/548367/definitions-of-the-route-keys-and-queuenames-for-s.html

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I recommend Option A. Have universal forwarders on endpoints send data to heavy forwarders which pass it on to the indexers.

---
If this reply helps you, Karma would be appreciated.

MMCC
Path Finder

Thank you for the fast reply! I'll further look into Option A.

Do you have any experience with "structured data"?

They seem to be quite special:
https://docs.splunk.com/Documentation/Splunk/8.0.3/Data/Extractfieldsfromfileswithstructureddata

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please ask that in a new question.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...