Splunk forwarders

Each machine that contains the log files generally runs a Splunk forwarder process. The job of this process is to read the logs on that machine or to run scripted inputs.

This installation is either of the following:

  • A full installation of Splunk, configured to forward data instead of indexing it
  • Splunk universal forwarder, which is essentially Splunk with everything needed for indexing or searching removed
  • With a full installation of Splunk, the process can be configured as one of two kinds of forwarder:
    • A light forwarder is configured not to parse events but, instead, to forward the raw stream of data to the indexers. This installation has the advantages that it uses very few resources on the machine running the forwarder ...

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.