Getting Data In

Universal Forwarder forwarding to Universal Forwarder

rdownie
Communicator

Is it possible to configure multiple Universal Forwarders to forward their data to another Universal Forwarder that would forward to an indexer? The logic here is to configure many servers in our DMZ with a Universal Forwarder which in turn would forward to a single Universal Forwarder that would then forward the data through the firewall to our indexer requiring only one firewall rule source to destination. If anyone has another suggestion for doing this, it would also be appreciated.
Thanks,
-Bob

Tags (3)
0 Karma
1 Solution

lukejadamec
Super Champion

You can set up the consolidating forwarder as a heavy forwarder. That is kind of what a heavy forwarder is for.

View solution in original post

lukejadamec
Super Champion

You can set up the consolidating forwarder as a heavy forwarder. That is kind of what a heavy forwarder is for.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...