Getting Data In

Configure an intermediate forwarder

Tumarbayev
Observer

Hello team. 
My task is that universal forwarder should collect the events from other hosts and then do realy to main server. How can i do it? 

Labels (1)
0 Karma

Tumarbayev
Observer

Last question. How can i configure the UF as a receiver on 9997? 

0 Karma

Tumarbayev
Observer

you mean i should configure the Universal forwarder on receiving mode and then on the sender server configure output to configured forwarder? 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Tumarbayev,

yes, you have to configure the Intermediate Forwarder bot as receiver and forwarder.

If you use an HF you can do all by GUI, if you use a UF, you have to condifure outputs.conf and inputs.conf; if you use a UF, remember to configure in limits.conf maxKBpm=0 otherwise you'll have queues issues.

Then, in the target UFs, you have to configure outputs.conf to point to the intermediate Forwarder.

Ciao.

Giuseppe

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Tumarbayev,

let me understand:

are you speaking of an intermediate Forwarder that colelcts logs from other Universal Forwarder and sends them to indexers, is it correct?

Are you speaking of an Heavy or an Universal Forwarder?

Anyway, youcan use as concentrator, both a Universal or an Heavy Forwarder, even if I usually use an HF.

At first you have to configure your HF Concentrator to forwarder logs to the Indexers.

Then you have to enable, on HF,  receiving on a port (default 9997).

At least, you have to configure your target UFs to send their logs to the HF using the define port (9997).

If you have HA requirements, it's better to have two HFs to avoid Single Points of Failure.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...