<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Send UF -&amp;gt; Deployment server traffic through a Proxy? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Send-UF-gt-Deployment-server-traffic-through-a-Proxy/m-p/522514#M18000</link>
    <description>Indexing traffic is not https it Splunk’s internal defined S2S. So I suppose that it don't use proxy unless you are defining those socks* on outputs.conf file.&lt;BR /&gt;I propose that you just test and report back if it works or not.&lt;BR /&gt;r. Ismo</description>
    <pubDate>Thu, 01 Oct 2020 14:41:20 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2020-10-01T14:41:20Z</dc:date>
    <item>
      <title>Send UF -&gt; Deployment server traffic through a Proxy?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Send-UF-gt-Deployment-server-traffic-through-a-Proxy/m-p/522329#M17980</link>
      <description>&lt;P&gt;We have a set of UF in a private network that is totally isolated from the Deployment server. For forwarder to indexer traffic we will use intermediate forwarders however we would also like to utilize the deployment server. Is it possible to configure a UF to point to a deployment server through a proxy?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 17:39:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Send-UF-gt-Deployment-server-traffic-through-a-Proxy/m-p/522329#M17980</guid>
      <dc:creator>ajiwanand</dc:creator>
      <dc:date>2020-09-30T17:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: Send UF -&gt; Deployment server traffic through a Proxy?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Send-UF-gt-Deployment-server-traffic-through-a-Proxy/m-p/522469#M17996</link>
      <description>Hi&lt;BR /&gt;I haven't try it, but based on configuration files this should be work.&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.6/Admin/Serverconf#Splunkd_http_proxy_configuration" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.6/Admin/Serverconf#Splunkd_http_proxy_configuration&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;And you probably already are using https as DS connection protocol? If yes then it should works. You can also use proxy for sending events to indexers if also those are behind proxy/socks. &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.6/Admin/Outputsconf#TCPOUT_SETTINGS" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.6/Admin/Outputsconf#TCPOUT_SETTINGS&lt;/A&gt; and check socks* parameters.&lt;BR /&gt;r. Ismo</description>
      <pubDate>Thu, 01 Oct 2020 12:03:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Send-UF-gt-Deployment-server-traffic-through-a-Proxy/m-p/522469#M17996</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-10-01T12:03:02Z</dc:date>
    </item>
    <item>
      <title>Re: Send UF -&gt; Deployment server traffic through a Proxy?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Send-UF-gt-Deployment-server-traffic-through-a-Proxy/m-p/522512#M17999</link>
      <description>&lt;P&gt;Hey soutamo,&lt;/P&gt;&lt;P&gt;Yes we'll be using&amp;nbsp; HTTPS as the DS protocol. My main requirement is to send only DS traffic to the proxy and indexer traffic through normal means. I wasn't entirely sure if using the splunkd as the protocol would allow for sending &lt;STRONG&gt;ONLY&lt;/STRONG&gt; HF to DS traffic via proxy? I'll give it a shot&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 14:38:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Send-UF-gt-Deployment-server-traffic-through-a-Proxy/m-p/522512#M17999</guid>
      <dc:creator>ajiwanand</dc:creator>
      <dc:date>2020-10-01T14:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: Send UF -&gt; Deployment server traffic through a Proxy?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Send-UF-gt-Deployment-server-traffic-through-a-Proxy/m-p/522514#M18000</link>
      <description>Indexing traffic is not https it Splunk’s internal defined S2S. So I suppose that it don't use proxy unless you are defining those socks* on outputs.conf file.&lt;BR /&gt;I propose that you just test and report back if it works or not.&lt;BR /&gt;r. Ismo</description>
      <pubDate>Thu, 01 Oct 2020 14:41:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Send-UF-gt-Deployment-server-traffic-through-a-Proxy/m-p/522514#M18000</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-10-01T14:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: Send UF -&gt; Deployment server traffic through a Proxy?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Send-UF-gt-Deployment-server-traffic-through-a-Proxy/m-p/522515#M18001</link>
      <description>&lt;P&gt;Fair point! I'll test it out and reply back later.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 14:42:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Send-UF-gt-Deployment-server-traffic-through-a-Proxy/m-p/522515#M18001</guid>
      <dc:creator>ajiwanand</dc:creator>
      <dc:date>2020-10-01T14:42:43Z</dc:date>
    </item>
    <item>
      <title>Re: Send UF -&gt; Deployment server traffic through a Proxy?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Send-UF-gt-Deployment-server-traffic-through-a-Proxy/m-p/522608#M18004</link>
      <description>&lt;P&gt;Hey&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tested this and confirmed that once you configure Splunkd to use a proxy, it will use the proxy to contact the DS and it does not affect the forwarder to indexer traffic as it uses S2S.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 23:50:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Send-UF-gt-Deployment-server-traffic-through-a-Proxy/m-p/522608#M18004</guid>
      <dc:creator>ajiwanand</dc:creator>
      <dc:date>2020-10-01T23:50:45Z</dc:date>
    </item>
  </channel>
</rss>

