Do to Security requirements I need to setup a forwarder between two networks, say A and B. My Splunk server is on network A, and I need servers on network B to send logs and events to the Splunk server on Network A using a forwarder or lightforwarder on a Redhat server. Any help with the configuration would be great.
Thanks
i would assume as long as there is a bridge to communicate between the two networks, the setup should be the same as all forwarder->indexer configurations.
Checking pinging/telneting and data connectivity between the networks is the first step. Then you can set up your indexer on Network B to FORWARD and INDEX the data.