Getting Data In

How to Send Linux Server logs with an external IP to splunk server with no external IP?

naseeb41
New Member

I have a Splunk server which doesn't have an external IP and all my servers with private IP can send their logs through Splunk Universal forwarder to Splunk, but I have couple of servers which are hosted elsewhere and can't talk to the splunk server because it doesn't have an external IP. Is there any way or solution to have my external servers send their logs to my internal Splunk server? I appreciate any suggestion or solution to this issue.

Thank you,

0 Karma

Richfez
SplunkTrust
SplunkTrust

You can daisy-chain forwarders. So, your externally-hosted servers can forward to some device in your DMZ, which forwards that on to your indexer. Here are the docs on how to configure an intermediate forwarder which will help you configure your intermediate device.

In a nutshell, the outside boxes would point to the Intermediate forwarder (which has one interface public and another private with both sides firewalled), then the intermediate forwarder points to your internal Wplunk server. Think of it like a proxy.

0 Karma

naseeb41
New Member

Thank you so much for your help. So, I just installed a universal forwarder on the server which is not in my DMZ and on output.conf I specified the name of the receiving server ( intermediate forwarder) in my DMZ with a public interface. Now where can I see in intermediate forwarder if the logs from other servers were forwarded and how to test the connection between intermediate forwarder and the universal forwarder? Do I have to change any other configurations?

I really appreciate your help.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...