<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Send Linux Server logs with an external IP to splunk server with no external IP? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-Send-Linux-Server-logs-with-an-external-IP-to-splunk/m-p/247722#M47769</link>
    <description>&lt;P&gt;You can daisy-chain forwarders.  So, your externally-hosted servers can forward to some device in your DMZ, which forwards that on to your indexer.  Here are the docs on &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.1/Forwarding/Configureanintermediateforwarder"&gt;how to configure an intermediate forwarder&lt;/A&gt; which will help you configure your intermediate device.&lt;/P&gt;

&lt;P&gt;In a nutshell, the outside boxes would point to the Intermediate forwarder (which has one interface public and another private with both sides firewalled), then the intermediate forwarder points to your internal Wplunk server.  Think of it like a proxy.&lt;/P&gt;</description>
    <pubDate>Sat, 09 Jul 2016 01:18:28 GMT</pubDate>
    <dc:creator>Richfez</dc:creator>
    <dc:date>2016-07-09T01:18:28Z</dc:date>
    <item>
      <title>How to Send Linux Server logs with an external IP to splunk server with no external IP?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-Send-Linux-Server-logs-with-an-external-IP-to-splunk/m-p/247721#M47768</link>
      <description>&lt;P&gt;I have a Splunk server which doesn't have an external IP and all my servers with private IP can send their logs through Splunk Universal forwarder to Splunk,  but I have couple of servers which are hosted elsewhere and can't talk to the splunk server because it doesn't have an external IP. Is there any way or solution to have my external servers send their logs to my internal Splunk server? I appreciate any suggestion or solution to this issue. &lt;/P&gt;

&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Sat, 09 Jul 2016 00:48:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-Send-Linux-Server-logs-with-an-external-IP-to-splunk/m-p/247721#M47768</guid>
      <dc:creator>naseeb41</dc:creator>
      <dc:date>2016-07-09T00:48:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to Send Linux Server logs with an external IP to splunk server with no external IP?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-Send-Linux-Server-logs-with-an-external-IP-to-splunk/m-p/247722#M47769</link>
      <description>&lt;P&gt;You can daisy-chain forwarders.  So, your externally-hosted servers can forward to some device in your DMZ, which forwards that on to your indexer.  Here are the docs on &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.1/Forwarding/Configureanintermediateforwarder"&gt;how to configure an intermediate forwarder&lt;/A&gt; which will help you configure your intermediate device.&lt;/P&gt;

&lt;P&gt;In a nutshell, the outside boxes would point to the Intermediate forwarder (which has one interface public and another private with both sides firewalled), then the intermediate forwarder points to your internal Wplunk server.  Think of it like a proxy.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Jul 2016 01:18:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-Send-Linux-Server-logs-with-an-external-IP-to-splunk/m-p/247722#M47769</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2016-07-09T01:18:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to Send Linux Server logs with an external IP to splunk server with no external IP?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-Send-Linux-Server-logs-with-an-external-IP-to-splunk/m-p/247723#M47770</link>
      <description>&lt;P&gt;Thank you so much for your help. So, I just installed a universal forwarder on the server which is not in my DMZ and on output.conf I specified the name of the receiving server ( intermediate forwarder) in my DMZ with a public interface. Now where can I see in intermediate forwarder if the logs from other servers were forwarded and how to test the connection between intermediate forwarder and the universal forwarder? Do I have to change any other configurations?&lt;/P&gt;

&lt;P&gt;I really appreciate your help.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2016 20:14:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-Send-Linux-Server-logs-with-an-external-IP-to-splunk/m-p/247723#M47770</guid>
      <dc:creator>naseeb41</dc:creator>
      <dc:date>2016-07-11T20:14:03Z</dc:date>
    </item>
  </channel>
</rss>

