Getting Data In

Can Splunk poll a forwarder

erick_thompson
Explorer

I have a public Universal Forwarder on a public server (public IP). I want to have a Splunk server hosted inside of the local network that consumes the data from the forwarder. I read the forwarder documentation, and didn't see a mention of this scenario. Can Splunk server poll the forwarder?

Thanks,
Erick

Tags (1)
0 Karma
1 Solution

dwaddle
SplunkTrust
SplunkTrust

Not as of Splunk 4.2 (and I don't know if this is available in 4.3 or not). As of 4.2 and all prior versions, Splunk expects that the forwarders push data to the indexer. You have some network-layer options like NATs and firewalls ACLs and VPNs and such (even an SSH tunnel) -- but your fowarder is going to have to initiate the connection to the indexer.

View solution in original post

Drainy
Champion

Another but much less secure and ideal option would be to setup the forwarder as an indexer instead.
Once setup as an indexer you can then set your indexer/search head inside the network to perform a distributed search against the indexer in the public domain. The logged data won't make it back into the inside network but it does provide the functionality to "poll" the outside device.

Again, not ideal.

0 Karma

dwaddle
SplunkTrust
SplunkTrust

Not as of Splunk 4.2 (and I don't know if this is available in 4.3 or not). As of 4.2 and all prior versions, Splunk expects that the forwarders push data to the indexer. You have some network-layer options like NATs and firewalls ACLs and VPNs and such (even an SSH tunnel) -- but your fowarder is going to have to initiate the connection to the indexer.

erick_thompson
Explorer

Thanks - that does make sense, but I am hoping to avoid messing with VPN or SSH.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...