Getting Data In

Can we use a single Splunk forwarder with access to Splunk SaaS and have on-prem servers communicate with the forwarder?

RXFK
New Member

We are getting ready to conduct a PoC on Splunk SaaS solution and for that, we have some challenges in opening firewall ports for each test machine. Is there any way to configure a single Splunk forwarder with access to Splunk SaaS and then the on-prem servers communicate with the forwarder. This way there is only one outbound connection.

0 Karma

shaskell_splunk
Splunk Employee
Splunk Employee

Yes, you can use a Universal Forwarder as an intermediate forwarder bridging the communication from your internal network to Splunk Cloud so you only have one outbound connection.

See the docs here:
http://docs.splunk.com/Documentation/Splunk/6.3.5/Forwarding/Configureanintermediateforwarder

Since it's for a POC I'm going to guess that the amount of data you're sending isn't terribly high volume. You typically would want multiple intermediate forwarders in a production environment for high availability and load balancing. For the purposes of a POC you'll probably be fine with a single forwarder.

Make sure you install the forwarder package that is provided by the Splunk Cloud team that has all the correct certificates to communicate with your Splunk Cloud instance on the intermediate forwarder.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...