I am trying to understand the splunk architecture and am confused by the articles on the topic.
I understand that forwarders retrieve information from the physical log files and forward those to indexers but what I don't understand is how forwarders achieve this.
More specifically:
- Do you need to install a forwarder onto every machine, virtual or physical, which generates log files which can push this information to the indexers or can there be a central forwarder which can connect to various application hosts and pull in the log information to forward to indexers or are both options available?
Any feedback would be greatly appreciated.
Thanks,
Bob