<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is Heavy Forwarder to Heavy Forwarder possible? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-Heavy-Forwarder-to-Heavy-Forwarder-possible/m-p/252157#M48479</link>
    <description>&lt;P&gt;Yes it is possible!  This guidance is tucked away at the bottom of this page: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.5/Forwarding/Forwarderdeploymenttopologies"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.5/Forwarding/Forwarderdeploymenttopologies&lt;/A&gt; &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Intermediate forwarding

To handle some advanced use cases, you might want to insert an intermediate forwarder between a group of forwarders and the indexer. In this type of scenario, the originating forwarders send data to a consolidating forwarder, which then forwards the data on to an indexer, usually after indexing it locally.

Typical use cases are situations where you need an intermediate index, either for "store-and-forward" requirements or to enable localized searching. (In this case, you would need to use a heavy forwarder.) You can also use an intermediate forwarder if you have some need to limit access to the indexer machine; for instance, for security reasons.

To enable intermediate forwarding, you need to configure the forwarder as a both a forwarder and a receiver. For information on how to configure a receiver, read "Enable a receiver". 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 01 Oct 2015 20:29:29 GMT</pubDate>
    <dc:creator>dflodstrom</dc:creator>
    <dc:date>2015-10-01T20:29:29Z</dc:date>
    <item>
      <title>Is Heavy Forwarder to Heavy Forwarder possible?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-Heavy-Forwarder-to-Heavy-Forwarder-possible/m-p/252156#M48478</link>
      <description>&lt;P&gt;We have a relatively closed network in which we plan to collect logs from.  This network resides on a larger "open" network that we don't want to have directly communicating to our internal network.&lt;/P&gt;

&lt;P&gt;Is it possible to send logs to a Heavy Forwarder on this "open" network, to another Heavy Forwarder in our DMZ, to our indexer?  I know this seems really odd (and it probably is), but I wanted to know if this is technically possible.  We are trying to work around policies in our network.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 20:23:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-Heavy-Forwarder-to-Heavy-Forwarder-possible/m-p/252156#M48478</guid>
      <dc:creator>aferone</dc:creator>
      <dc:date>2015-10-01T20:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: Is Heavy Forwarder to Heavy Forwarder possible?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-Heavy-Forwarder-to-Heavy-Forwarder-possible/m-p/252157#M48479</link>
      <description>&lt;P&gt;Yes it is possible!  This guidance is tucked away at the bottom of this page: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.5/Forwarding/Forwarderdeploymenttopologies"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.5/Forwarding/Forwarderdeploymenttopologies&lt;/A&gt; &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Intermediate forwarding

To handle some advanced use cases, you might want to insert an intermediate forwarder between a group of forwarders and the indexer. In this type of scenario, the originating forwarders send data to a consolidating forwarder, which then forwards the data on to an indexer, usually after indexing it locally.

Typical use cases are situations where you need an intermediate index, either for "store-and-forward" requirements or to enable localized searching. (In this case, you would need to use a heavy forwarder.) You can also use an intermediate forwarder if you have some need to limit access to the indexer machine; for instance, for security reasons.

To enable intermediate forwarding, you need to configure the forwarder as a both a forwarder and a receiver. For information on how to configure a receiver, read "Enable a receiver". 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 01 Oct 2015 20:29:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-Heavy-Forwarder-to-Heavy-Forwarder-possible/m-p/252157#M48479</guid>
      <dc:creator>dflodstrom</dc:creator>
      <dc:date>2015-10-01T20:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: Is Heavy Forwarder to Heavy Forwarder possible?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-Heavy-Forwarder-to-Heavy-Forwarder-possible/m-p/252158#M48480</link>
      <description>&lt;P&gt;Thank you!  I actually did read that documentation, but it wasn't clear to me if it was referring to heavy forwarders.  Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 20:38:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-Heavy-Forwarder-to-Heavy-Forwarder-possible/m-p/252158#M48480</guid>
      <dc:creator>aferone</dc:creator>
      <dc:date>2015-10-01T20:38:42Z</dc:date>
    </item>
  </channel>
</rss>

