7. What are the unique benefits of getting data into splunk instance via forwarder?
Benefits of getting data into splunk instance via forwarder :
- Bandwidth throttling
- TCP connection
- Encrypted SSL connection
For transferring data from forwarder to an indexer
The data forwarded to the indexer are load balanced by default even if one indexer is down due to network outage or maintenance purpose the data can be always routed to the another indexer instance in short time.
Also forwarder caches the event locally before forwarding it thus creates backup of data.
8. Which splunk roles can share the same machine?
In small deployment the most of the roles can be shared on same machine as as Search head, Indexer and License master.
In larger deployment to host each host on standalone host
- Indexers and search head should have physically dedicated machine using Virtual machines for running the instance separately is not the solution because there are some guidelines for it using computer resources and spinning multiple virtual machines on the same physical hardware can cause performance degradation.
- you can spin another VM on same instance for hosting the cluster master as long as Deployment server is not hosted parallel on a VM on that same instance because the number of connections coming to deployment server will be very high.
- This is because deployment server not only caters to the request coming from deployment master but also request coming from forwarder.
GIPHY App Key not set. Please check settings