Getting Data In

Getting Data to Splunk from clients outside our LAN

mmeredith
New Member

I am trying to setup our Splunk architecture to be able to receive events from clients/workstations outside our local network. The simplest solution is just making the main indexer externally accessible, but we don't want to do that. Is there a way to setup a Heavy Forwarder like a proxy to receive events from external clients and then send them to the main indexer? I haven't been able to find anything related to this when I try to research.

Thanks.

Labels (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, you could set up a HF and make it accessible to external clients.  This is a common way to handle situations like this.  The HF is like a DMZ in that outsiders can connect to it, but the network only allows traffic from the HF to reach the indexers.

BTW, there's no such thing as a "main indexer" in Splunk.  Indexers are referred to as "search peers" because they're all equal.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...