Deployment Architecture

automatic lookup on splunkforwarder

mbrussk
Engager

Hello,

is it possible, to implement automatic lookups on a splunk forwarder?
The reason for this request is, that i´ve already installed the splunk forwarder on a linux-based vpn-server.
The forwarder already monitors the log file of the vpn-process (racoon) and forward it to our central splunk indexer.
But there is a need, to add data to the logfile, befor it is send to the indexer, because the data which has to be added are only available at run-time on the linux system itself and depends on the information of each log line. Therefor i´ve no chance with an lookup at the central splunk indexer.

regards
Michael

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The Universal Forwarder only forwards. To do anything else, you must install a Heavy Forwarder.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

The Universal Forwarder only forwards. To do anything else, you must install a Heavy Forwarder.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...