Getting Data In

Heavy forwarder

hethu
Path Finder

Hi, 

I am trying to figure out if i need a heavy forwarder or not; from what I have read in the documentation, a heavy forwarder is needed to be able to use addons slik splunk DB Connect, is that correct?

If so; can the heavy forwarder forward to a universal forwarder,  that forwards to Splunk Cloud?

Heavy Forwarder --> Universal Forwarder (DMZ) --> Splunk Cloud

I presume it is possible, but I just wanted to be 100% sure.  

Labels (2)
0 Karma

alonsocaio
Contributor

Hi @hethu,

Actually you can forward your logs from Heavy Forwarder directly to Splunk Cloud. I guess this would be the recommended architecture for this case.

Do you have any network restrictions for communication between your server and Splunk Cloud? If this is the case, maybe you should deploy a Heavy Forwarder instead an Universal Forwarder on DMZ. I have not tested sending logs between two forwarders, but I guess this is possible. 

hethu
Path Finder

Thanks for replying.

You are correct, i need two forwarders because of network restrictions. So i am trying to figure out if i need two heavy forwarders, or just 1 heavy + 1 universal

0 Karma

alonsocaio
Contributor

Understood. My suggestion would be to deploy a Heavy Forwarder on DMZ. I guess It would give you more control on inputs, routing and parsing than the Universal Forwarder. But looking at the docs, It seems to be possible to use the Universal Forwarder as intermediate. Here you have a more detailed comparison about the different types of Splunk forwarders (https://docs.splunk.com/Documentation/Splunk/8.1.0/Forwarding/Typesofforwarders#Forwarder_comparison)

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...