Getting Data In

Universal Forwarder forwarding to Universal Forwarder

rdownie
Communicator

Is it possible to configure multiple Universal Forwarders to forward their data to another Universal Forwarder that would forward to an indexer? The logic here is to configure many servers in our DMZ with a Universal Forwarder which in turn would forward to a single Universal Forwarder that would then forward the data through the firewall to our indexer requiring only one firewall rule source to destination. If anyone has another suggestion for doing this, it would also be appreciated.
Thanks,
-Bob

Tags (3)
0 Karma
1 Solution

lukejadamec
Super Champion

You can set up the consolidating forwarder as a heavy forwarder. That is kind of what a heavy forwarder is for.

View solution in original post

lukejadamec
Super Champion

You can set up the consolidating forwarder as a heavy forwarder. That is kind of what a heavy forwarder is for.

Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...