Getting Data In

Universal Forwarder forwarding to Universal Forwarder

rdownie
Communicator

Is it possible to configure multiple Universal Forwarders to forward their data to another Universal Forwarder that would forward to an indexer? The logic here is to configure many servers in our DMZ with a Universal Forwarder which in turn would forward to a single Universal Forwarder that would then forward the data through the firewall to our indexer requiring only one firewall rule source to destination. If anyone has another suggestion for doing this, it would also be appreciated.
Thanks,
-Bob

Tags (3)
0 Karma
1 Solution

lukejadamec
Super Champion

You can set up the consolidating forwarder as a heavy forwarder. That is kind of what a heavy forwarder is for.

View solution in original post

lukejadamec
Super Champion

You can set up the consolidating forwarder as a heavy forwarder. That is kind of what a heavy forwarder is for.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how ...