Getting Data In

Getting Data to Splunk from clients outside our LAN

mmeredith
New Member

I am trying to setup our Splunk architecture to be able to receive events from clients/workstations outside our local network. The simplest solution is just making the main indexer externally accessible, but we don't want to do that. Is there a way to setup a Heavy Forwarder like a proxy to receive events from external clients and then send them to the main indexer? I haven't been able to find anything related to this when I try to research.

Thanks.

Labels (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, you could set up a HF and make it accessible to external clients.  This is a common way to handle situations like this.  The HF is like a DMZ in that outsiders can connect to it, but the network only allows traffic from the HF to reach the indexers.

BTW, there's no such thing as a "main indexer" in Splunk.  Indexers are referred to as "search peers" because they're all equal.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...