Splunk® Enterprise

Getting Data In

Acrobat logo Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Acrobat logo Download topic as PDF

Forward data

This topic explains the Select Forwarders page that Splunk Enterprise loads when you click the Forward button on the Add data page.

Important: Use this page only if you have a single instance of Splunk Enterprise acting as an indexer and deployment server. If you have multiple hosts that perform indexing, see "About deployment server and forwarder management" in the Updating Splunk Enterprise Instances manual.

The Select Forwarders page

When you access the Forward page, the following page appears:

62 SelectSource Forward.png

You can define server classes and add forwarders to those classes.

This page only displays forwarders that you configured to forward data and act as deployment clients to this instance. If you have not configured any forwarders, the page warns you of this.

For a forwarder to appear in the list, you must do the following:

  • Configure the forwarder as a deployment client. This means that a deployment server can manage the configurations for the forwarder. See "Configure deployment clients" in the Updating Splunk Enterprise Instances manual.
  • Confirm that the forwarder makes a successful connection to the deployment server.

After you see the forwarder in the list, you can configure it to add data.

1. In Select Server Class, click one of the options:

  • New to create a new server class, or if an existing server class does not match the group of forwarders that you want to configure an input for.
  • Existing to use an existing server class.

2. In the Available host(s) pane, choose the forwarder(s) that you want this instance to receive data from. The forwarders move from the Available host(s) pane to the Selected host(s) pane.

Note: A server class must contain hosts of a certain platform. You cannot, for example, put Windows and *nix hosts in the same server class.

3. (Optional) You can add all of the hosts by clicking the add all link, or remove all hosts by selecting the remove all link.

4. If you chose New in "Select server class", enter a unique name for the server class that you will remember. Otherwise, select the server class you want from the drop-down list.

5. Click Next. The "Select Source" page shows source types that are valid for the forwarders that you selected.

6. Select the data sources that you want the forwarders to send data to this instance.

7. Click the green Next button to proceed to the Set Sourcetype page.

Last modified on 19 February, 2016
Monitor data
The Set Sourcetype page

This documentation applies to the following versions of Splunk® Enterprise: 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters