Deployment Architecture

Is there a way for a Splunk Enterprise deployment to behave as a UF as well?



I'd like to know whether a Splunk Enterprise deployment can act as a UF to another Splunk Enterprise deployment. What I'd like to do is be able to index and analyze log data using a Splunk Enterprise deployment within a private network, and then send a subset of that data to a Splunk Enterprise cloud deployment. The reasons for this intermediate step are:

  1. Log data contains sensitive information that must remain within the private network
  2. Pre-elaboration is needed to strip sensitive data for cloud transfer
  3. Reporting is required on sensitive data within private network

Is there a configuration that exists within Splunk Enterprise that enables the forwarding of it's data to a separate Splunk Enterprise deployment, or do I have to use a dedicated UF on the same machine and create saved searches that output CSV files for it to transfer to cloud?

Thank you and best regards,


0 Karma

0 Karma
Get Updates on the Splunk Community!

BSides Splunk 2022 - The Call for Papers is now Open!

TLDR; Main Site: CFP Site: CFP Opens: December 15th, ...

Sending Metrics to Splunk Enterprise With the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...