Getting Data In

Universal Forwarder forwarding to Universal Forwarder

rdownie
Communicator

Is it possible to configure multiple Universal Forwarders to forward their data to another Universal Forwarder that would forward to an indexer? The logic here is to configure many servers in our DMZ with a Universal Forwarder which in turn would forward to a single Universal Forwarder that would then forward the data through the firewall to our indexer requiring only one firewall rule source to destination. If anyone has another suggestion for doing this, it would also be appreciated.
Thanks,
-Bob

Tags (3)
0 Karma
1 Solution

lukejadamec
Super Champion

You can set up the consolidating forwarder as a heavy forwarder. That is kind of what a heavy forwarder is for.

View solution in original post

lukejadamec
Super Champion

You can set up the consolidating forwarder as a heavy forwarder. That is kind of what a heavy forwarder is for.

Get Updates on the Splunk Community!

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Using the Splunk Threat Research Team’s Latest Security Content

REGISTER HERE Tech Talk | Security Edition Did you know the Splunk Threat Research Team regularly releases ...