What is the Splunk universal forwarder?

The Splunk universal forwarder is a free, dedicated version of Splunk Enterprise that contains only the essential components needed to forward data. HELPnet uses the universal forwarder to gather data from a variety of inputs and forward your machine data to Splunk indexers. The data is then available for searching.

The universal forwarder is designed to run on production servers, having minimal CPU and memory usage and the least impact possible on mission-critical software.

Forwarders communicate with deployment servers, which then send configurations to the client forwarder. These configurations tell the forwarder what data to send to which indexers.

The forwarder sends the data encrypted to the indexers. Once the data is written to the Splunk index, searching can begin immediately; thus, searches are up to date within moments of the event occurrence.

Notes:
  • Universal forwarders do not have a web or application interface. Once installed, you must make configuration changes at the command line in both Windows and Unix- or Linux-based systems.
  • Best practices:
    • Use the universal forwarder when possible as a data collection method.
    • Stop and start the universal forwarder from the command line.
  • The Splunk license model is to bill by the amount of GB of daily data ingestion.

Benefits

Benefits of using the Splunk universal forwarder:

  • Data consolidation from all types of inputs
  • Reduces indexer load on the Data Center side (push vs. pull method)
  • Improves resiliency by buffering data when needed, sending to available indexers and switching to others when needed (auto load balance)
  • Administered remotely with the deployment server

This is document bfln in the Knowledge Base.
Last modified on 2015-12-07 00:00:00.

  • Fill out this form to submit your issue to the UITS Support Center.
  • Please note that you must be affiliated with Indiana University to receive support.
  • All fields are required.

Please provide your IU email address. If you currently have a problem receiving email at your IU account, enter an alternate email address.

  • Fill out this form to submit your comment to the IU Knowledge Base.
  • If you are affiliated with Indiana University and need help with a computing problem, please use the I need help with a computing problem section above, or contact your campus Support Center.

Please provide your IU email address. If you currently have a problem receiving email at your IU account, enter an alternate email address.