Greetings, At my current company, we're using Splunk Cloud and I'm looking to deploya new HeavyForwarder to forward data along to the Cloud instance. The question is, what's the a...
Hello Community,
I am having issues connecting my Universal Forwarder with aHeavyForwarder.
I have the following set up: UF-->HF-->IDx
I can see the logs from HF to IDx, but not sure w...
Hello - I have 3 HFs and about 150 UFs and 1 deployment server and other instances. In a new configuration, how can I use the DS to deployapps to only these 3 HFs and UFs, not to other i...
Hi all.
Like the subject, can i tell an HF not to PARSE the events, just do a banal tcp forwarding of the raw data? I can replace an HF with a banal TCP-FORWARDING tool, and it works. But the q...
Hi,
We recently had to deployaheavyforwarder into the Splunk architecture.
Last time, the flow was from a source->IDX.directly. Now we had to deploy like this : source-> HF-> IDX....
...hich has me very confused.
First, I'm not sure whether the Splunk app for Stream needs to be installed on our Indexers, HeavyForwarders, or our Deployment Server. (Btw, we use a stand-alone deploy...
...t is not showing up in the GUI. The end goal is to have data coming in from a universal forwarder on a Windows server to a Centos heavyforwarder, which then passes up the data to Splunk Cloud. A p...
...eads, Indexers and HeavyForwarders. We have also opened required receiving ports on both Indexer and HF.
On the other hand, we have around 200 UF's, can someone please tell me, if we need to g...
we have the following setup
2 heavyforwarders (HF) forwarding data to 4 indexers
We just added another 100 Universal forwarders (UF) to the environment so now we have about 800 UFs c...