What are Splunk forwarders?

What are Splunk forwarders?

In the article about roles. we treated a decent amount of different roles. But up until now we did not see yet who is responsible for getting the data to the indexers. Here is where forwarders come in. Universal Forwarder (UF) The Splunk Universal Forwarder is a very...
What are Splunk forwarders?

What are Splunk’s server roles?

In a distributed environment we will no longer have all functions performed by the same server, Each server will be designated one or more roles. These roles are also important from a monitoring perspective. As we will see in a later article Splunk’s Monitoring...
What are Splunk forwarders?

What are Splunk’s deployment types?

Splunk has two ways of being deployed. One is a standalone box and the other is called a ‘distributed deployment’. What are the differences? In a standalone deployment you will have one server that does all of the work. In a distributed deployment you will...
What are Splunk forwarders?

What are Splunk’s magic 6?

In our last article about Splunk metadata we spoke about the sourcetype field being one of the metadadata fields. In our article about getting data in Splunk we also saw that at a certain moment we had to chose a sourcetype for our data. What we did not do was open...