Splunk Search

How to use forwarder

balajsoz
Path Finder

Hi,
I have installed splunk forwarder in the same machine where splunk is installed.i need to know is that correct?or i need to install the forwarder in a different machine from where the splunk should pick the data or to monitor the data?pls help

Tags (1)
0 Karma
1 Solution

Wilcooley
Path Finder

The Splunk forwarder package is a subset of the Splunk package, installed into a different directory, so adding the forwarder is redundant since the installed Splunk package can do all of the file monitoring that the forwarder does. I would be surprised if you can have them both running at the same time.

View solution in original post

wagnerbianchi
Splunk Employee
Splunk Employee

Normally, the Splunk Universal Forwarder is used to consolidate machine data from remote machines, collecting and forwarding information to a Splunk Instance (in a sense of centralization).

In case you are setting up a Forwarder on the same machine as Splunk Instance just for a test, it's pretty acceptable, but, this is not the case to apply in production.

There is a online Universal Forwarder manual which is pretty straightforward:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Introducingtheuniversalforwarder

Give you a chance to read and understand more about that...

Cheers, WB

0 Karma

Wilcooley
Path Finder

The Splunk forwarder package is a subset of the Splunk package, installed into a different directory, so adding the forwarder is redundant since the installed Splunk package can do all of the file monitoring that the forwarder does. I would be surprised if you can have them both running at the same time.

Drainy
Champion

If you make the relevant configuration changes you could run them on the same machine at the same time, but the use-cases for this are pretty minimal. In most instances you're better off configuring the indexer to index and forward.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...