Getting Data In

Can we use a single Splunk forwarder with access to Splunk SaaS and have on-prem servers communicate with the forwarder?

RXFK
New Member

We are getting ready to conduct a PoC on Splunk SaaS solution and for that, we have some challenges in opening firewall ports for each test machine. Is there any way to configure a single Splunk forwarder with access to Splunk SaaS and then the on-prem servers communicate with the forwarder. This way there is only one outbound connection.

0 Karma

shaskell_splunk
Splunk Employee
Splunk Employee

Yes, you can use a Universal Forwarder as an intermediate forwarder bridging the communication from your internal network to Splunk Cloud so you only have one outbound connection.

See the docs here:
http://docs.splunk.com/Documentation/Splunk/6.3.5/Forwarding/Configureanintermediateforwarder

Since it's for a POC I'm going to guess that the amount of data you're sending isn't terribly high volume. You typically would want multiple intermediate forwarders in a production environment for high availability and load balancing. For the purposes of a POC you'll probably be fine with a single forwarder.

Make sure you install the forwarder package that is provided by the Splunk Cloud team that has all the correct certificates to communicate with your Splunk Cloud instance on the intermediate forwarder.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...