CARVIEW |
heavy forwarder
heavy forwarder
noun
A type of forwarder, which is a Splunk Enterprise instance that sends data to another Splunk Enterprise instance or to a third-party system.
A heavy forwarder has a smaller footprint than a Splunk Enterprise indexer but retains most of the capabilities of an indexer. An exception is that it cannot perform distributed searches. You can disable some services, such as Splunk Web, to further reduce its footprint size.
Unlike other forwarder types, a heavy forwarder parses data before forwarding it and can route data based on criteria such as source or type of event. It can also index data locally while forwarding the data to another indexer.
In most situations, the universal forwarder is the best way to forward data to indexers. Its main limitation is that it forwards only unparsed data, except in certain cases, such as structured data. You must use a heavy forwarder to route data based on event contents.
Related terms
For more information
In Forwarding Data:
- saved search
- scheduled alert
- scheduled report
- scheduled search
- scheduler
- scripted authentication
- scripted input
- search
- search affinity
- Search app
- search artifact
- search assistant
- search execution directive
- search factor
- search field
- search filter
- search head
- search head cluster
- search head cluster captain
- search head cluster member
- search head clustering
- search head pooling
- search head targeting
- search job
- Search Job Inspector
- search macro
- search management
- search mode
- search peer
- search peer replication
- Search Processing Language
- search scheduler
- search time
- search timeline
- search view
- searchability
- searchable
- segment
- send to background
- sequence template
- series
- server
- server class
- Settings
- SignalFlow
- SignalFx Smart Agent receiver
- Simple XML
- single-instance deployment
- single-site indexer cluster
- SmartStore
- source
- source type
- span
- span tag
- SPL
- SPL2
- SPL2 statement
- Splunk Answers
- Splunk Distribution of OpenTelemetry Collector
- Splunk OpenTelemetry Collector
- Splunk platform
- Splunk UI
- Splunk Web
- Splunk Web Framework
- Splunkbase
- splunkd
- SplunkJS Stack
- stack mode
- standalone search head
- stanza
- static captain
- streaming command
- subsearch
- summary index