Getting Data In

Does data indexed and forwarded from a heavy forwarder count against the Splunk data license?

mookiie2005
Communicator

We have a Heavy forwarder load balancing data feeds from a TCP/UDP feeds to the two indexers we are using. My question is does the data indexed and then forwarded from the heavy forwarder to either indexer count against the Splunk license? This would basically charge the customer twice to index the same data. Once at the heavy forwarder and than again at the indexers. Would this change if the IndexandForward attribute was set to false?

1 Solution

kristian_kolb
Ultra Champion

Yes. A heavy forwarder is essentially an indexer, where indexing has been turned off. Turning it back on, like with indexAndForward, will require a license in order to make the events searchable on that machine.

As for charging for indexing the same data twice, that used to be one of the ways to make a Splunk installation more HA/DR-like, and I believe that you could get some sort of license discount for those types of scenarios. Since version 5, there is index replication to cater for that need (which lets your indexers make copies already indexed data at no extra cost, apart from the extra storage required).

Setting indexAndForward=false would let your Heavy Forwarder act as just that.

Hope this clarifies things a bit,

K

View solution in original post

kristian_kolb
Ultra Champion

Yes. A heavy forwarder is essentially an indexer, where indexing has been turned off. Turning it back on, like with indexAndForward, will require a license in order to make the events searchable on that machine.

As for charging for indexing the same data twice, that used to be one of the ways to make a Splunk installation more HA/DR-like, and I believe that you could get some sort of license discount for those types of scenarios. Since version 5, there is index replication to cater for that need (which lets your indexers make copies already indexed data at no extra cost, apart from the extra storage required).

Setting indexAndForward=false would let your Heavy Forwarder act as just that.

Hope this clarifies things a bit,

K

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...