Getting Data In

Connectivity issues while onboarding the data

bobba40
New Member

Forwarding data from forwarder to indexer where there is no connectivity . what does this connectivity mean . And to solve that we are planning to use syslog along with Heavy forwarder at each network to index the data to Splunk cloud . Please suggest if its fesable and any one implemenet please help to get the flow.

0 Karma
1 Solution

solarboyz1
Builder

Not really clear on what is meant by "where there is no connectivity . what does this connectivity mean"
If your forwarder cannot connect to your indexers, it will not be able to send events to it.

Let me describe what we have configured, which I believe is similar:

On-prem systems send syslog to the syslog process on an on-prem HF

The syslog process on the HF writes the events log files.
The Splunk process on the HF monitors [monitor:///var/syslog/...] the syslog files
The HF then forwards the data to the indexing tier.
(We also use PCS clustering to provide HA syslog service, since Syslog is not very resilient).

The indexing tier can be in the cloud or on-prem, the heavy forwarders would just need connectivity to the indexers.
You can even send from multiple HFs -> Centralized HFs -> Cloud indexers if you want to reduce the openings to the cloud.

View solution in original post

0 Karma

solarboyz1
Builder

Not really clear on what is meant by "where there is no connectivity . what does this connectivity mean"
If your forwarder cannot connect to your indexers, it will not be able to send events to it.

Let me describe what we have configured, which I believe is similar:

On-prem systems send syslog to the syslog process on an on-prem HF

The syslog process on the HF writes the events log files.
The Splunk process on the HF monitors [monitor:///var/syslog/...] the syslog files
The HF then forwards the data to the indexing tier.
(We also use PCS clustering to provide HA syslog service, since Syslog is not very resilient).

The indexing tier can be in the cloud or on-prem, the heavy forwarders would just need connectivity to the indexers.
You can even send from multiple HFs -> Centralized HFs -> Cloud indexers if you want to reduce the openings to the cloud.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

The Trust Gap: Why a Data Foundation is Fundamental to an Agentic Enterprise

The Trust Gap: Why a data foundation is fundamental to an  Agentic Enterprise.   Agentic AI is transforming ...

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...