Deployment Architecture

Splunk Heavy Fowarder to Splunk Cloud using DB connect

jsmorgan1it
New Member

Okay, our goal is to capture data from a local database using DB connect to query the data and Splunk Heavy Fowarder to push the data up to a Splunk Cloud instance.

Where we are:

  1. Installed Splunk Enterprise
  2. Installed Splunk DB connect on Splunk Heavy Forwarder
  3. Deployed Splunk Cloud Instance
  4. Configured Forwarding/Receiving and Forwarding default settings on the Splunk Heavy Forwarder
  5. Configured Forwarding settings on Splunk Heavy Forwarder to point to Splunk cloud server (www.server.splunkcloud.com:9997)
  6. Outputs.conf file in the LOCAL directory is pointing to our Splunk cloud hostname and port

The help we need:

  1. The Outputs.conf file in the FORWARDER directory has a very different format that the outputs.conf file in the local directory. Do we need to update this outputs.conf file as well if so what data do we input and in what line? (See attached screenshot)
  2. How do we create an index on the Splunk Cloud so that data is pushed from the Heavy Forwarder directly into that index in the cloud?

Thank you!

Tags (1)
0 Karma
1 Solution

jsmorgan1it
New Member

Nareshinsvu, once an index is created and enabled on the Splunk cloud environment, how do we ensure that data pushed from our Heavy Forwarder is sent directly into the index we created and enabled?

0 Karma

nareshinsvu
Builder

You should probably raise a Support ticket for your data integrity and security related queries. As per their docs,

Data Segregation for Splunk Cloud
Splunk Cloud deployments run in a secured environment, and your data exists on virtually dedicated servers to ensure it remains isolated from other customers’ data.

0 Karma

jsmorgan1it
New Member

My question was unrelated to data integrity and security but rather, once an index is created how do we ensure data from the Heavy Forwarder pushes the data collected into the index we establish on the Splunk Cloud. Do you know the answer to this?

0 Karma

jsmorgan1it
New Member

I would think somewhere on the Heavy Forwarder you will have to specify where (what index name) you want the data to reside in once pushed to the Splunk Cloud, no?

0 Karma

nareshinsvu
Builder

Do go through the conf files involved in Data forwarding before jumping into your environment.

outputs.conf - Indexer discovery etc happens here
inputs.conf - target index, source and sourcetype to be defined here
props.conf & transforms.conf - Filter and extractions of your data to be defined here.

0 Karma

jsmorgan1it
New Member

That's it! Thank you.

0 Karma

realhippo33
Explorer

Sounds like you didn't install the forwarder app you can download from your Splunk Cloud instance. It will have all the right settings and certificates to send data to Splunk Cloud.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...