Splunk Search

How to use forwarder

balajsoz
Path Finder

Hi,
I have installed splunk forwarder in the same machine where splunk is installed.i need to know is that correct?or i need to install the forwarder in a different machine from where the splunk should pick the data or to monitor the data?pls help

Tags (1)
0 Karma
1 Solution

Wilcooley
Path Finder

The Splunk forwarder package is a subset of the Splunk package, installed into a different directory, so adding the forwarder is redundant since the installed Splunk package can do all of the file monitoring that the forwarder does. I would be surprised if you can have them both running at the same time.

View solution in original post

wagnerbianchi
Splunk Employee
Splunk Employee

Normally, the Splunk Universal Forwarder is used to consolidate machine data from remote machines, collecting and forwarding information to a Splunk Instance (in a sense of centralization).

In case you are setting up a Forwarder on the same machine as Splunk Instance just for a test, it's pretty acceptable, but, this is not the case to apply in production.

There is a online Universal Forwarder manual which is pretty straightforward:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Introducingtheuniversalforwarder

Give you a chance to read and understand more about that...

Cheers, WB

0 Karma

Wilcooley
Path Finder

The Splunk forwarder package is a subset of the Splunk package, installed into a different directory, so adding the forwarder is redundant since the installed Splunk package can do all of the file monitoring that the forwarder does. I would be surprised if you can have them both running at the same time.

Drainy
Champion

If you make the relevant configuration changes you could run them on the same machine at the same time, but the use-cases for this are pretty minimal. In most instances you're better off configuring the indexer to index and forward.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...