About forwarding and receiving
If you already know about forwarders and want the instructions on how to install them, see:
- Install a Windows universal forwarder from an installer in the Forwarder Manual.
- Install a *nix universal forwarder in the Forwarder Manual.
- Deploy a heavy forwarder
Sample forwarding layout
This diagram shows three forwarders that send data to a single receiver (an indexer), which then indexes the data and makes it available for searching:
Forwarders represent a much more robust solution for data forwarding than raw network feeds, with their capabilities for:
- Tagging of metadata (source, source type, and host)
- Configurable buffering
- Data compression
- SSL security
- Use of any available network ports
Learn more about forwarding and receiving
- To learn more about the fundamentals of Splunk Enterprise distributed deployment, see the Distributed Deployment Manual.
- For more information on the types of deployment topologies that you can create with forwarders, see Forwarder deployment topologies in this manual.
- To learn about what intermediate forwarding is, see Intermediate forwarding in this manual.
- To learn about the different types of forwarders available, see Types of forwarders.
- To learn about universal forwarders, see the Universal Forwarder manual.
Types of forwarders
This documentation applies to the following versions of Splunk Cloud Platform™: 8.2.2109, 8.0.2007, 8.1.2011, 8.0.2006, 8.1.2009, 8.1.2012, 8.1.2101, 8.1.2103, 8.2.2104, 8.2.2105 (latest FedRAMP release), 8.2.2106, 8.2.2107