Getting Data In

How to forward data when forwarder cannot contact indexer through firewall?

joshuapetitt
Path Finder

Hi all,

I have a situation where there are servers from which we wish to get logs into Splunk.

However, we cannot use the traditional Universal Forwarder because these servers are not allowed to connect through the firewall to the indexer.

We can go from "inside" the firewalled network to these servers "outside" the network.

So we could perform some sort of API calls if necessary.

Is there a way to set up a Heavy Forwarder to poll the servers "outside" the network and pull in the logs?

Does the UF support being a "server" instead of a "client", meaning UF would expose an API that could be queried by an HF?

Any and all suggestions (aside from reconfiguring firewall) are welcome, thanks!

Labels (2)
Tags (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

at least I haven’t heard pull option for core splunk. 
One way which come to my mind is e.g. Control-M or any other batch system which can transfer files from A to B etc. But if you are needing real time logs then this isn’t an option.

r. Ismo

isoutamo
SplunkTrust
SplunkTrust

Hi

another opinion could be a SOCKS5 proxy if your organization has it in use. https://docs.splunk.com/Documentation/Forwarder/8.0.5/Forwarder/ConfigureaforwardertouseaSOCKSproxy
r. Ismo

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...