<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Heavy Fowarder to Splunk Cloud using DB connect in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Heavy-Fowarder-to-Splunk-Cloud-using-DB-connect/m-p/457501#M16047</link>
    <description>&lt;P&gt;You should probably raise a Support ticket for your data integrity and security related queries. As per their docs, &lt;/P&gt;

&lt;P&gt;&lt;EM&gt;Data Segregation for Splunk Cloud&lt;BR /&gt;
Splunk Cloud deployments run in a secured environment, and your data exists on virtually dedicated servers to ensure it remains isolated from other customers’ data.&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Aug 2019 05:32:08 GMT</pubDate>
    <dc:creator>nareshinsvu</dc:creator>
    <dc:date>2019-08-21T05:32:08Z</dc:date>
    <item>
      <title>Splunk Heavy Fowarder to Splunk Cloud using DB connect</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Heavy-Fowarder-to-Splunk-Cloud-using-DB-connect/m-p/457497#M16043</link>
      <description>&lt;P&gt;Okay, our goal is to capture data from a local database using DB connect to query the data and Splunk Heavy Fowarder to push the data up to a Splunk Cloud instance. &lt;/P&gt;

&lt;P&gt;Where we are: &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Installed Splunk Enterprise &lt;/LI&gt;
&lt;LI&gt;Installed Splunk DB connect on Splunk Heavy  Forwarder&lt;/LI&gt;
&lt;LI&gt;Deployed Splunk Cloud Instance &lt;/LI&gt;
&lt;LI&gt;Configured Forwarding/Receiving and Forwarding default settings on the Splunk Heavy Forwarder &lt;/LI&gt;
&lt;LI&gt;Configured Forwarding settings on Splunk Heavy Forwarder to point to Splunk cloud server (&lt;A href="http://www.server.splunkcloud.com:9997"&gt;www.server.splunkcloud.com:9997&lt;/A&gt;)&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Outputs.conf file in the LOCAL directory is pointing to our Splunk  cloud hostname and port&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;&lt;STRONG&gt;The help we need&lt;/STRONG&gt;: &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;The Outputs.conf file in the FORWARDER directory has a very different format that the outputs.conf file in the local directory. Do we need to update this outputs.conf file as well if so what data do we input and in what line? (See attached screenshot)&lt;/LI&gt;
&lt;LI&gt;How do we create an index on the Splunk Cloud so that data is pushed from the Heavy Forwarder directly into that index in the cloud?&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 00:17:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Heavy-Fowarder-to-Splunk-Cloud-using-DB-connect/m-p/457497#M16043</guid>
      <dc:creator>jsmorgan1it</dc:creator>
      <dc:date>2019-08-21T00:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Heavy Fowarder to Splunk Cloud using DB connect</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Heavy-Fowarder-to-Splunk-Cloud-using-DB-connect/m-p/457498#M16044</link>
      <description>&lt;P&gt;Sounds like you didn't install the forwarder app you can download from your Splunk Cloud instance. It will have all the right settings and certificates to send data to Splunk Cloud.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 02:11:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Heavy-Fowarder-to-Splunk-Cloud-using-DB-connect/m-p/457498#M16044</guid>
      <dc:creator>realhippo33</dc:creator>
      <dc:date>2019-08-21T02:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Heavy Fowarder to Splunk Cloud using DB connect</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Heavy-Fowarder-to-Splunk-Cloud-using-DB-connect/m-p/457499#M16045</link>
      <description>&lt;P&gt;1)&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/148813/steps-to-setup-splunk-forwarder-for-splunk-in-the-cloud.html"&gt;https://answers.splunk.com/answers/148813/steps-to-setup-splunk-forwarder-for-splunk-in-the-cloud.html&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Forwarder/7.3.1/Forwarder/HowtoforwarddatatoSplunkCloud"&gt;https://docs.splunk.com/Documentation/Forwarder/7.3.1/Forwarder/HowtoforwarddatatoSplunkCloud&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;2)&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/7.2.6/User/ManageIndexes"&gt;https://docs.splunk.com/Documentation/SplunkCloud/7.2.6/User/ManageIndexes&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 05:18:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Heavy-Fowarder-to-Splunk-Cloud-using-DB-connect/m-p/457499#M16045</guid>
      <dc:creator>nareshinsvu</dc:creator>
      <dc:date>2019-08-21T05:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Heavy Fowarder to Splunk Cloud using DB connect</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Heavy-Fowarder-to-Splunk-Cloud-using-DB-connect/m-p/457500#M16046</link>
      <description>&lt;P&gt;Nareshinsvu, once an index is created and enabled on the Splunk cloud environment, how do we ensure that data pushed from our Heavy Forwarder is sent directly into the index we created and enabled?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 05:25:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Heavy-Fowarder-to-Splunk-Cloud-using-DB-connect/m-p/457500#M16046</guid>
      <dc:creator>jsmorgan1it</dc:creator>
      <dc:date>2019-08-21T05:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Heavy Fowarder to Splunk Cloud using DB connect</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Heavy-Fowarder-to-Splunk-Cloud-using-DB-connect/m-p/457501#M16047</link>
      <description>&lt;P&gt;You should probably raise a Support ticket for your data integrity and security related queries. As per their docs, &lt;/P&gt;

&lt;P&gt;&lt;EM&gt;Data Segregation for Splunk Cloud&lt;BR /&gt;
Splunk Cloud deployments run in a secured environment, and your data exists on virtually dedicated servers to ensure it remains isolated from other customers’ data.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 05:32:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Heavy-Fowarder-to-Splunk-Cloud-using-DB-connect/m-p/457501#M16047</guid>
      <dc:creator>nareshinsvu</dc:creator>
      <dc:date>2019-08-21T05:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Heavy Fowarder to Splunk Cloud using DB connect</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Heavy-Fowarder-to-Splunk-Cloud-using-DB-connect/m-p/457502#M16048</link>
      <description>&lt;P&gt;My question was unrelated to data integrity and security but rather, once an index is created how do we ensure data from the Heavy Forwarder pushes the data collected into the index we establish on the Splunk Cloud. Do you know the answer to this?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 05:35:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Heavy-Fowarder-to-Splunk-Cloud-using-DB-connect/m-p/457502#M16048</guid>
      <dc:creator>jsmorgan1it</dc:creator>
      <dc:date>2019-08-21T05:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Heavy Fowarder to Splunk Cloud using DB connect</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Heavy-Fowarder-to-Splunk-Cloud-using-DB-connect/m-p/457503#M16049</link>
      <description>&lt;P&gt;I would think somewhere on the Heavy Forwarder you will have to specify where (what index name) you want the data to reside in once pushed to the Splunk Cloud, no?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 05:38:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Heavy-Fowarder-to-Splunk-Cloud-using-DB-connect/m-p/457503#M16049</guid>
      <dc:creator>jsmorgan1it</dc:creator>
      <dc:date>2019-08-21T05:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Heavy Fowarder to Splunk Cloud using DB connect</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Heavy-Fowarder-to-Splunk-Cloud-using-DB-connect/m-p/457504#M16050</link>
      <description>&lt;P&gt;Do go through the &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.1/Admin/Listofconfigurationfiles"&gt;conf files&lt;/A&gt; involved in Data forwarding before jumping into your environment.&lt;/P&gt;

&lt;P&gt;outputs.conf - Indexer discovery etc happens here&lt;BR /&gt;
inputs.conf - target index, source and sourcetype to be defined here&lt;BR /&gt;
props.conf &amp;amp; transforms.conf - Filter and extractions of your data to be defined here.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 05:47:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Heavy-Fowarder-to-Splunk-Cloud-using-DB-connect/m-p/457504#M16050</guid>
      <dc:creator>nareshinsvu</dc:creator>
      <dc:date>2019-08-21T05:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Heavy Fowarder to Splunk Cloud using DB connect</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Heavy-Fowarder-to-Splunk-Cloud-using-DB-connect/m-p/457505#M16051</link>
      <description>&lt;P&gt;That's it! Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 05:51:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Heavy-Fowarder-to-Splunk-Cloud-using-DB-connect/m-p/457505#M16051</guid>
      <dc:creator>jsmorgan1it</dc:creator>
      <dc:date>2019-08-21T05:51:35Z</dc:date>
    </item>
  </channel>
</rss>

