Getting Data In

How can I set up a forwarder to send logs to an indexer from a different network segment?

vonas
Engager

I did some searching and can't find an answer, although I suspect there is a simple answer...

I have a network segment that I need to forward logs out of. We have Windows, Cisco and Linux equipment in this segment. I wanted to send all these logs to a Universal forwarder, then from there have that universal forwarder send it to the indexer. This was we only have one hole in the firewall.

I am unsure of how to setup this one universal forwarder. How can I configure it to take input from all three different kind of systems and forward on to indexer along with it's own logs?

0 Karma

skoelpin
SplunkTrust
SplunkTrust

You should use a heavy forwarder rather than a universal forwarder. A heavy forwarder is a full Splunk instance and can be setup through the user interface

https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Forwarding/Deployaheavyforwarder

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...