<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to pull data from DMZ Heavy Forwarder in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-pull-data-from-DMZ-Heavy-Forwarder/m-p/630303#M26673</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your response.&lt;BR /&gt;&lt;BR /&gt;Any tips on what configuration and port need to open between the UFs/HFs ?&lt;/P&gt;</description>
    <pubDate>Thu, 09 Feb 2023 14:45:43 GMT</pubDate>
    <dc:creator>randqm</dc:creator>
    <dc:date>2023-02-09T14:45:43Z</dc:date>
    <item>
      <title>How to pull data from DMZ Heavy Forwarder?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-pull-data-from-DMZ-Heavy-Forwarder/m-p/630289#M26671</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I want to install HF or UF on our DMZ environment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;The Indexer is on the LAN.&lt;BR /&gt;&lt;BR /&gt;I is not allow to communicate from the DMZ to the LAN .&lt;/P&gt;
&lt;P&gt;I need that the logs from the DMZ will be pulled to the Indexer in the LAN (using HF or any other solution).&lt;/P&gt;
&lt;P&gt;Please share your insight on how to setup this from your experience .&lt;BR /&gt;&lt;BR /&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 16:10:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-pull-data-from-DMZ-Heavy-Forwarder/m-p/630289#M26671</guid>
      <dc:creator>randqm</dc:creator>
      <dc:date>2023-02-09T16:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull data from DMZ Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-pull-data-from-DMZ-Heavy-Forwarder/m-p/630297#M26672</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249195"&gt;@randqm&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you have to put one (or better two) UFs or HFs to concentrate all the logs from DMZ or outside (e.g. Cloud Services).&lt;/P&gt;&lt;P&gt;So you have to open only the routes between these HFs or UFs and Indexers.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 14:33:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-pull-data-from-DMZ-Heavy-Forwarder/m-p/630297#M26672</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-09T14:33:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull data from DMZ Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-pull-data-from-DMZ-Heavy-Forwarder/m-p/630303#M26673</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your response.&lt;BR /&gt;&lt;BR /&gt;Any tips on what configuration and port need to open between the UFs/HFs ?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 14:45:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-pull-data-from-DMZ-Heavy-Forwarder/m-p/630303#M26673</guid>
      <dc:creator>randqm</dc:creator>
      <dc:date>2023-02-09T14:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull data from DMZ Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-pull-data-from-DMZ-Heavy-Forwarder/m-p/630304#M26674</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249195"&gt;@randqm&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the usual ports you're using in your Splunk infrastructure:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;usually 9997 is used to send data to indexers (monodirectional),&lt;/LI&gt;&lt;LI&gt;8089 (bidirectional) between UFs (or HFs) and Deployment Server for the configurations.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 14:49:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-pull-data-from-DMZ-Heavy-Forwarder/m-p/630304#M26674</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-09T14:49:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull data from DMZ Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-pull-data-from-DMZ-Heavy-Forwarder/m-p/630305#M26675</link>
      <description>&lt;P&gt;But my issue is that any communication from the DMZ to LAN is not allow.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":frowning_face:"&gt;☹️&lt;/span&gt;&lt;BR /&gt;In the opposite direction it is allowed.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 14:53:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-pull-data-from-DMZ-Heavy-Forwarder/m-p/630305#M26675</guid>
      <dc:creator>randqm</dc:creator>
      <dc:date>2023-02-09T14:53:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull data from DMZ Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-pull-data-from-DMZ-Heavy-Forwarder/m-p/630306#M26676</link>
      <description>&lt;P&gt;That's a typical problem because Splunk works mostly on "push" principle - forwarders get their data from various inputs but it's them who connect to the indexers (or intermediate forwarders), not the other way around. Splunk doesn't have a built-in "pull" mode.&lt;/P&gt;&lt;P&gt;So you can either set up a designated intermediate forwarder(s) which will be the only ones allowed to connect to LAN (but I understand that it can be not that easy with some strict traffic policies) or use some external solution to - for example - write events to a file on some host in DMZ. You'd then connect connect from your LAN to this host and read events from those files.&lt;/P&gt;&lt;P&gt;But I don't think there's a ready solution for this.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 15:02:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-pull-data-from-DMZ-Heavy-Forwarder/m-p/630306#M26676</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-02-09T15:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull data from DMZ Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-pull-data-from-DMZ-Heavy-Forwarder/m-p/630307#M26677</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249195"&gt;@randqm&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if no commuminations are alloweb from DMZ to LAN, you haven't ways to send data!&lt;/P&gt;&lt;P&gt;You can secure the connections between machines using SSL and certificates, and define very hard rules for the firewalls, but if DMZ cannot send data to LAN, there isn't any solution!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 15:02:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-pull-data-from-DMZ-Heavy-Forwarder/m-p/630307#M26677</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-09T15:02:36Z</dc:date>
    </item>
  </channel>
</rss>

