Deployment Architecture

Is there a way for a Splunk Enterprise deployment to behave as a UF as well?

andrewtrobec
Motivator

Hello,

I'd like to know whether a Splunk Enterprise deployment can act as a UF to another Splunk Enterprise deployment. What I'd like to do is be able to index and analyze log data using a Splunk Enterprise deployment within a private network, and then send a subset of that data to a Splunk Enterprise cloud deployment. The reasons for this intermediate step are:

  1. Log data contains sensitive information that must remain within the private network
  2. Pre-elaboration is needed to strip sensitive data for cloud transfer
  3. Reporting is required on sensitive data within private network

Is there a configuration that exists within Splunk Enterprise that enables the forwarding of it's data to a separate Splunk Enterprise deployment, or do I have to use a dedicated UF on the same machine and create saved searches that output CSV files for it to transfer to cloud?

Thank you and best regards,

Andrew

0 Karma

harsmarvania57
Ultra Champion
0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...