Deployment Architecture

Heavy Forwarder to Splunk Cloud via Socks Proxy

andrewparkes
Loves-to-Learn

Hi,

 

We have a project to implement splunk so that it talks out to splunk cloud, via a proxy server.

To do this, i believe we need to configure the heavy forwarder to connect to the proxy using socks5, port 1080, as per this article: 

https://docs.splunk.com/Documentation/Splunk/9.0.2/Forwarding/ConfigureaforwardertouseaSOCKSproxy

I beleive i've done this correctly, i think, and we also think the proxy is configured correctly. Yet we aren't seeing the data flow into splunk.

 

Am i missing something with the config on the forwarder, or is it really just as that article presents it? Looking in the deployment server, i can see the test endpoints we've added are visible, so all that seems to be working, its now getting this out and into the cloud we need.

 

All new to me splunk, so trying to work it out on the fly, therefore an pointers in the right direction would be appreciated

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...