Splunk forwarders

Each machine that contains the log files generally runs a Splunk forwarder process. The job of this process is to read the logs on that machine or to run scripted inputs.

This installation is either of the following:

The most important configurations to a forwarder installation are:

The default setting for a light forwarder is very low to prevent flooding the network or overtaxing the forwarding machine. This value can usually be increased safely. It is often increased to the limits of the networking hardware.

We will discuss deploying the forwarder in the Deploying the Splunk binary section in this chapter.