Getting Data In

Universal Forwarder forwarding to Universal Forwarder

rdownie
Communicator

Is it possible to configure multiple Universal Forwarders to forward their data to another Universal Forwarder that would forward to an indexer? The logic here is to configure many servers in our DMZ with a Universal Forwarder which in turn would forward to a single Universal Forwarder that would then forward the data through the firewall to our indexer requiring only one firewall rule source to destination. If anyone has another suggestion for doing this, it would also be appreciated.
Thanks,
-Bob

Tags (3)
0 Karma
1 Solution

lukejadamec
Super Champion

You can set up the consolidating forwarder as a heavy forwarder. That is kind of what a heavy forwarder is for.

View solution in original post

lukejadamec
Super Champion

You can set up the consolidating forwarder as a heavy forwarder. That is kind of what a heavy forwarder is for.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...