Getting Data In

Is there a sample configuration available for intermediate forwarding? (application servers -> intermediate forwarder -> indexers)

sravankaripe
Communicator

In my use case, I need to forward logs from application servers to intermediate forwarders, then from the intermediate forwarder to Splunk Indexers. Can anybody help me in providing a sample configuration file for this?

0 Karma

somesoni2
Revered Legend

See this (old post but you can refer to latest documentation for each step)

https://answers.splunk.com/answers/10429/is-there-an-example-configuration-available-for-an-intermed...

Basically

Setup Forwarding on Universal forwarder (installed on your application servers) - (should forward to your Intermediate forwarder) http://docs.splunk.com/Documentation/Splunk/6.4.3/Forwarding/EnableforwardingonaSplunkEnterpriseinst...
Setup Receiving and Forwarding on Intermediate forwarder : (should forwarder to Indexers) http://docs.splunk.com/Documentation/Splunk/6.4.3/Forwarding/Configureanintermediateforwarder
Setup Receiving on Indexer: http://docs.splunk.com/Documentation/Forwarder/6.4.3/Forwarder/Enableareceiver

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...