Setting up a heavy forwarder
A heavy forwarder is presented in Splunk docs and other sources as being a type of forwarder that sends data to another Splunk Enterprise instance or to a third-party system. It is also suggested that a heavy forwarder can have a smaller footprint than a Splunk Enterprise indexer (by disabling some services such as Splunk Web), but retains most of the capabilities of an indexer. Finally, the docs will state that a heavy forwarder parses data before forwarding it and can route data based on criteria such as a source or type of event, and that it can index data locally while forwarding data to another indexer. However, you won't find a download file for a heavy forwarder on the Splunk site, nor will you find a specific ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access