Greetings, At my current company, we're using Splunk Cloud and I'm looking to deploya new HeavyForwarder to forward data along to the Cloud instance. The question is, what's the a...
Hello Community,
I am having issues connecting my Universal Forwarder with aHeavyForwarder.
I have the following set up: UF-->HF-->IDx
I can see the logs from HF to IDx, but not sure w...
Hello - I have 3 HFs and about 150 UFs and 1 deployment server and other instances. In a new configuration, how can I use the DS to deployapps to only these 3 HFs and UFs, not to other i...
Hi all.
Like the subject, can i tell an HF not to PARSE the events, just do a banal tcp forwarding of the raw data? I can replace an HF with a banal TCP-FORWARDING tool, and it works. But the q...
Hi,
We recently had to deployaheavyforwarder into the Splunk architecture.
Last time, the flow was from a source->IDX.directly. Now we had to deploy like this : source-> HF-> IDX....
hi experts
trying to deploya HF and forward logs to 2 different indexers. clone data i have 2 UFs feeding windows and syslog logs respectively to a HF.
This is my HF output conf, i think t...
we have the following setup
2 heavyforwarders (HF) forwarding data to 4 indexers
We just added another 100 Universal forwarders (UF) to the environment so now we have about 800 UFs c...
...eads, Indexers and HeavyForwarders. We have also opened required receiving ports on both Indexer and HF.
On the other hand, we have around 200 UF's, can someone please tell me, if we need to g...
Hello,
I am currently doing a Splunk implementation where I have multiple Universal Forwarders which will be sending information to my HeavyForwarders, where we will be doing a lot of f...