Deployment Architecture

Heavy Forwarder to Splunk Cloud via Socks Proxy

andrewparkes
Loves-to-Learn

Hi,

 

We have a project to implement splunk so that it talks out to splunk cloud, via a proxy server.

To do this, i believe we need to configure the heavy forwarder to connect to the proxy using socks5, port 1080, as per this article: 

https://docs.splunk.com/Documentation/Splunk/9.0.2/Forwarding/ConfigureaforwardertouseaSOCKSproxy

I beleive i've done this correctly, i think, and we also think the proxy is configured correctly. Yet we aren't seeing the data flow into splunk.

 

Am i missing something with the config on the forwarder, or is it really just as that article presents it? Looking in the deployment server, i can see the test endpoints we've added are visible, so all that seems to be working, its now getting this out and into the cloud we need.

 

All new to me splunk, so trying to work it out on the fly, therefore an pointers in the right direction would be appreciated

Labels (1)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...