Deployment Architecture

Can Splunk Universal Forwarder Forward the Data to Splunk Enterprise using UDP protocol?

Shamnad
Observer

We have a deployment scenario where Splunk UF forwards the Data to Splunk Enterprise using "One Way Communication", so is there any way we can have the Splunk UF Communicates with the Splunk UE through UDP Protocol?

Labels (1)
0 Karma

Shamnad
Observer

Our scenario is like we are having multiple Universal Forwarders forwarding data to Splunk Enterprise through One Way, in between the UF's and Splunk Enterprise there is a Proxy server which carries the TCP packets from Multiple UF's and the Splunk Enterprise. When the data reaches the Enterprise it will shows the host IP of the Proxy Server address, so all the forwarded events will be treated as the events from the Proxy server, is there any way we can get the host details/IP address of each sources(UF's).

0 Karma

thambisetty
SplunkTrust
SplunkTrust

you can have TCP also to have one way communication. meaning connection will be always initiated by Universal forwarder. you need to open a firewall rule src to dest on port 9997 ( default).

I don't think you can forward over UDP to Splunk Enterprise from Splunk Universal forwarder. you need to have syslog installed on Splunk Enterprise server for that.

————————————
If this helps, give a like below.
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...