Getting Data In

How to Send Linux Server logs with an external IP to splunk server with no external IP?

naseeb41
New Member

I have a Splunk server which doesn't have an external IP and all my servers with private IP can send their logs through Splunk Universal forwarder to Splunk, but I have couple of servers which are hosted elsewhere and can't talk to the splunk server because it doesn't have an external IP. Is there any way or solution to have my external servers send their logs to my internal Splunk server? I appreciate any suggestion or solution to this issue.

Thank you,

0 Karma

Richfez
SplunkTrust
SplunkTrust

You can daisy-chain forwarders. So, your externally-hosted servers can forward to some device in your DMZ, which forwards that on to your indexer. Here are the docs on how to configure an intermediate forwarder which will help you configure your intermediate device.

In a nutshell, the outside boxes would point to the Intermediate forwarder (which has one interface public and another private with both sides firewalled), then the intermediate forwarder points to your internal Wplunk server. Think of it like a proxy.

0 Karma

naseeb41
New Member

Thank you so much for your help. So, I just installed a universal forwarder on the server which is not in my DMZ and on output.conf I specified the name of the receiving server ( intermediate forwarder) in my DMZ with a public interface. Now where can I see in intermediate forwarder if the logs from other servers were forwarded and how to test the connection between intermediate forwarder and the universal forwarder? Do I have to change any other configurations?

I really appreciate your help.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...