Getting Data In

How to get data in from DMZ servers?

Lwoods
Path Finder

Hello,

I have a few Linux devices that are located within the DMZ.  My 3 Splunk servers (Search Head, Indexer, Deployment) are inside my network.  I've installed the forwarders on my dmz servers, and set up the set-poll-deployment command (myserver.com:8089)  to ensure it's pointing to the deployment server.   There is no communication from the dmz servers to the deployment server 

I did 2 tests:

1. I was able to connect from 1 dmz server to the deployment server.   Result: Connection good.

2. I was not able to connect from the deployment server to the dmz server:  Result: Connection refused

Are there other options to get the dmz servers to connect?   

Thanks

 

Labels (1)
0 Karma

Lwoods
Path Finder

I had ports 8089, and 9997 opened on the firewall.   What is the Linux command to test the connection from the DMZ server to the Deployment server?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

There is no need for the DS to connect to the DMZ server.  Forwarders always initiate communication with the DS.

You also, however, need to ensure the forwarder can communicate with the indexer.

---
If this reply helps you, Karma would be appreciated.

Lwoods
Path Finder

I had ports 8089, and 9997 opened on the firewall.   What is the Linux command to test the connection from the DMZ server to the Deployment server?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You can use telnet, curl, nc, or even cat.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...