Deployment Architecture

Splunk cloud forwarders

rakeshksingh
New Member

Hi All,

How to make connection between Splunk cloud and Splunk enterprise local to exchange data just like forwarders ?

Thanks
Rk

Tags (1)
0 Karma

lcavaliere_splu
Splunk Employee
Splunk Employee

Hello rakeshksingh,

From your Splunk Cloud UI, launch the "Universal Forwarder" app and this will bring you to a page with instructions on how to configure forwarding to your Splunk Cloud instance. This includes a link to a credentials package that you will need to download and install onto each forwarder (this is essentially an app which sets up your outputs.conf to point to the Splunk Cloud indexer cluster and also has the required security certificates).

Please note also that applies also to Splunk Enterprise instances (e.g. Heavy Weight Forwarders) that you would like to use to forward data to Splunk Cloud (i.e. this is not only just for configuring Universal Forwarders).

And here is a link to document page that is a good starting point for configuring this:
https://docs.splunk.com/Documentation/Forwarder/7.2.3/Forwarder/HowtoforwarddatatoSplunkCloud

Cheers

FrankVl
Ultra Champion

Can you elaborate a bit more on the setup you have so far and what you want to accomplish?

0 Karma

rakeshksingh
New Member

Hi FrankVi,

I have my local splunk trail version and Splunk cloud . Local splunk runs on localhost then how to map local splunk and cloud splunk for forwarding logs in between.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...