About forwarding and receiving
If you already know about forwarders and want the instructions on how to install them, see:
- Install a Windows universal forwarder from an installer in the Forwarder Manual.
- Install a *nix universal forwarder in the Forwarder Manual.
- Deploy a heavy forwarder
Sample forwarding layout
This diagram shows three forwarders that send data to a single receiver (an indexer), which then indexes the data and makes it available for searching:
Forwarders represent a much more robust solution for data forwarding than raw network feeds, with their capabilities for:
- Tagging of metadata (source, source type, and host)
- Configurable buffering
- Data compression
- SSL security
- Use of any available network ports
Learn more about forwarding and receiving
- To learn more about the fundamentals of Splunk Enterprise distributed deployment, see the Distributed Deployment Manual.
- For more information on the types of deployment topologies that you can create with forwarders, see Forwarder deployment topologies in this manual.
- To learn about what intermediate forwarding is, see Intermediate forwarding in this manual.
- To learn about the different types of forwarders available, see Types of forwarders.
- To learn about universal forwarders, see the Universal Forwarder manual.
Types of forwarders
This documentation applies to the following versions of Splunk® Enterprise: 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8, 7.2.9, 7.2.10, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.7, 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.1.0