About forwarding and receiving
If you already know about forwarders and want the instructions on how to install them, see:
- Install a Windows universal forwarder in the Forwarder Manual.
- Install a *nix universal forwarder in the Forwarder Manual.
- Deploy a heavy forwarder
Sample forwarding layout
This diagram shows three forwarders that send data to a single receiver (an indexer), which then indexes the data and makes it available for searching:
Forwarders represent a much more robust solution for data forwarding than raw network feeds, with their capabilities for:
- Tagging of metadata (source, source type, and host)
- Configurable buffering
- Data compression
- SSL security
- Use of any available network ports
Learn more about forwarding and receiving
- To learn more about the fundamentals of Splunk Enterprise distributed deployment, see the Distributed Deployment Manual.
- For more information on the types of deployment topologies that you can create with forwarders, see Forwarder deployment topologies in this manual.
- To learn about what intermediate forwarding is, see Intermediate forwarding in this manual.
- To learn about the different types of forwarders available, see Types of forwarders.
- To learn about universal forwarders, see the Universal Forwarder manual.
Types of forwarders
This documentation applies to the following versions of Splunk Cloud Platform™: 8.2.2201, 8.2.2202, 8.2.2203, 9.0.2205, 9.0.2208, 9.0.2209 (latest FedRAMP release), 8.2.2112