Quantcast
Channel: Questions in topic: "heavy-forwarder"
Viewing all articles
Browse latest Browse all 727

Indexer and Heavy Forwarder in once?

$
0
0
Hello community, we would like to forward a subset of syslog data to a 3rd party syslog host. So, no problem, this is possible with a forwarder or a heavy forwarder (http://docs.splunk.com/Documentation/Splunk/6.3.0/Forwarding/Forwarddatatothird-partysystemsd). But, I want to do this on our (single) indexer. What happens if I add a outputs.conf, and so change the indexer to a heavy forwarder? Is still everything (search, dashboards, alerts, ...) working as it should, plus the posibilities of a heavy forwarder? Thanks for your help.

Viewing all articles
Browse latest Browse all 727

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>