Deployment Architecture

Splunk cloud forwarders

rakeshksingh
New Member

Hi All,

How to make connection between Splunk cloud and Splunk enterprise local to exchange data just like forwarders ?

Thanks
Rk

Tags (1)
0 Karma

lcavaliere_splu
Splunk Employee
Splunk Employee

Hello rakeshksingh,

From your Splunk Cloud UI, launch the "Universal Forwarder" app and this will bring you to a page with instructions on how to configure forwarding to your Splunk Cloud instance. This includes a link to a credentials package that you will need to download and install onto each forwarder (this is essentially an app which sets up your outputs.conf to point to the Splunk Cloud indexer cluster and also has the required security certificates).

Please note also that applies also to Splunk Enterprise instances (e.g. Heavy Weight Forwarders) that you would like to use to forward data to Splunk Cloud (i.e. this is not only just for configuring Universal Forwarders).

And here is a link to document page that is a good starting point for configuring this:
https://docs.splunk.com/Documentation/Forwarder/7.2.3/Forwarder/HowtoforwarddatatoSplunkCloud

Cheers

FrankVl
Ultra Champion

Can you elaborate a bit more on the setup you have so far and what you want to accomplish?

0 Karma

rakeshksingh
New Member

Hi FrankVi,

I have my local splunk trail version and Splunk cloud . Local splunk runs on localhost then how to map local splunk and cloud splunk for forwarding logs in between.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...