Use forwarders to get data into Splunk Enterprise
Splunk forwarders consume data and send it to an indexer. Forwarders require minimal resources and have little impact on performance, so they can usually reside on the machines where the data originates.
For example, if you have a number of Apache Web servers that generate data that you want to search centrally, you can set up forwarders on the Apache hosts. The forwarders take the Apache data and send it to your Splunk Enterprise deployment for indexing, which consolidates, stores, and makes the data available for searching. Because of their reduced resource footprint, forwarders have a minimal performance impact on the Apache servers.
Similarly, you can install forwarders on your employees' Windows desktops. These forwarders can send logs and other data to your Splunk Enterprise deployment, where you can view the data as a whole to track malware or other issues.
What forwarders do
Forwarders get data from remote machines. Unlike raw network feeds, forwarders have the following capabilities:
- Tag metadata (source, sourcetype, and host)
- Buffer data
- Compress data
- Use SSL security
- Use any available network ports
- Run scripted inputs locally
Forwarders usually do not index the data, but instead, forward the data to a Splunk Enterprise deployment that does the indexing and searching. A Splunk Enterprise deployment can process data that comes from many forwarders. For detailed information on forwarders, see the Forwarding Data or Universal Forwarder manuals.
In most Splunk Enterprise deployments, forwarders serve as the primary consumers of data. In a large Splunk Enterprise deployment, you might have hundreds or even thousands of forwarders that consume data and forward for consolidation.
How to configure forwarder inputs
The following is a high-level overview of the steps to configure forwarder inputs for Splunk Enterprise.
- Configure a Splunk Enterprise host to receive the data.
- Determine the kind of forwarder you want to put on the host with the data.
- You can use a heavy forwarder, which is a full Splunk Enterprise instance with forwarding turned on, or a universal forwarder, which is its own installation package.
- The type of forwarder you use depends on the performance requirements for the host and whether you need to transform the data in any way as it comes into Splunk Enterprise.
- Download Splunk Enterprise or the universal forwarder for the platform and architecture of the host with the data.
- Install the forwarder onto the host.
- Enable forwarding on the host and specify a destination
- Configure inputs for the data that you want to collect from the host. You can use Splunk Web if the forwarder is a full Splunk Enterprise instance.
- Confirm that data from the forwarder arrives at the receiving indexer.
Here are the main ways that you can configure data inputs on a forwarder:
- Specify inputs during the initial deployment of the forwarder.
- For Windows forwarders, specify common inputs during the forwarder installation process.
- For *nix forwarders, specify inputs directly after installation.
- Use the CLI.
- Edit the inputs.conf file.
- Install the app or add-on that contains the inputs you want.
- Use Splunk Web to configure the inputs and a deployment server to copy the resulting inputs.conf file to forwarders.
Forwarder topologies and deployments
- For information on forwarders, including use cases, typical topologies, and configurations, see About forwarding and receiving in the Forwarding Data manual.
- For details on how to deploy the universal forwarder, including how to use the deployment server to simplify distribution of configuration files and apps to multiple forwarders, see Install the forwarder credentials on many forwarders using a deployment server in the Universal Forwarder manual.
Use forwarders to get data into Splunk Cloud Platform
Use apps and add-ons to get data in
This documentation applies to the following versions of Splunk Cloud Platform™: 9.1.2312, 8.2.2112, 8.2.2201, 8.2.2202, 8.2.2203, 9.0.2205, 9.0.2208, 9.0.2209, 9.0.2303, 9.0.2305 (latest FedRAMP release), 9.1.2308