<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UF remote to on-prem Splunk Enterprise best practices in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/UF-remote-to-on-prem-Splunk-Enterprise-best-practices/m-p/561437#M100044</link>
    <description>&lt;P&gt;Not sure if it's a "best practice", but consider putting 2 or more HFs in a DMZ.&amp;nbsp; The UFs forward to them which forward to the indexers.&amp;nbsp; Use a SSL certificate to keep out unwanted traffic to the HFs.&lt;/P&gt;</description>
    <pubDate>Thu, 29 Jul 2021 19:53:03 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-07-29T19:53:03Z</dc:date>
    <item>
      <title>UF remote to on-prem Splunk Enterprise best practices</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-remote-to-on-prem-Splunk-Enterprise-best-practices/m-p/561408#M100040</link>
      <description>&lt;P&gt;We have several remote and traveling systems that we need to forward logs from to our on-prem Spunk environment. Splunk Cloud is not an option.&lt;/P&gt;&lt;P&gt;Are there any best practices for system config or architecture?&lt;/P&gt;&lt;P&gt;Is it possible to use a reverse proxy for inbound connections to the deployment server?&lt;/P&gt;&lt;P&gt;Should the reverse proxy have a splunk UF or should an intermediate HF be used to forward to the indexer tier?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jul 2021 16:31:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-remote-to-on-prem-Splunk-Enterprise-best-practices/m-p/561408#M100040</guid>
      <dc:creator>mikefg</dc:creator>
      <dc:date>2021-07-29T16:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: UF remote to on-prem Splunk Enterprise best practices</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-remote-to-on-prem-Splunk-Enterprise-best-practices/m-p/561437#M100044</link>
      <description>&lt;P&gt;Not sure if it's a "best practice", but consider putting 2 or more HFs in a DMZ.&amp;nbsp; The UFs forward to them which forward to the indexers.&amp;nbsp; Use a SSL certificate to keep out unwanted traffic to the HFs.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jul 2021 19:53:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-remote-to-on-prem-Splunk-Enterprise-best-practices/m-p/561437#M100044</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-07-29T19:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: UF remote to on-prem Splunk Enterprise best practices</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-remote-to-on-prem-Splunk-Enterprise-best-practices/m-p/561544#M100047</link>
      <description>&lt;P&gt;Thanks. We also have some potential options for collecting logs when connected to our VPN.&lt;/P&gt;&lt;P&gt;Last I looked I don't recall options for local log storage on a UF (only buffer and queue) to be uploaded when connected to a VPN, is this still the case?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 14:33:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-remote-to-on-prem-Splunk-Enterprise-best-practices/m-p/561544#M100047</guid>
      <dc:creator>mikefg</dc:creator>
      <dc:date>2021-07-30T14:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: UF remote to on-prem Splunk Enterprise best practices</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-remote-to-on-prem-Splunk-Enterprise-best-practices/m-p/561546#M100048</link>
      <description>&lt;P&gt;AFAIK, queueing within the UF hasn't changed.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 14:43:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-remote-to-on-prem-Splunk-Enterprise-best-practices/m-p/561546#M100048</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-07-30T14:43:18Z</dc:date>
    </item>
  </channel>
</rss>

