Getting Data In

Using UF to forward data to local Heavy Forwarder and then on to Cloud

damo66a
Explorer

I may have missed a topic in my search but is there a way to do the following (im also fairly new to Splunk so be gentle 😁 )

We have a server locked down on our network and has no outside access but we can configure internal (server to server) access. 

Is there a way to use a Universal Forwarder on that server to forward to the local on prem Heavy Forwarder and then relay those to our Splunk Cloud?

Thanks in advance

0 Karma
1 Solution

aasabatini
Motivator

Hello @damo66a  again,

yes you can configure the uf to send to HF and in the end at splunkcloud

be careful to to configure your outputs.conf

https://docs.splunk.com/Documentation/Splunk/8.1.3/Admin/outputsconf

https://docs.splunk.com/Documentation/Forwarder/8.1.3/Forwarder/HowtoforwarddatatoSplunkEnterprise

suggestion, if you have a huge size of eventdata you can think to use 2 hf to use the splunk load-balancing options

 

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”

View solution in original post

0 Karma

aasabatini
Motivator

Hello @damo66a  again,

yes you can configure the uf to send to HF and in the end at splunkcloud

be careful to to configure your outputs.conf

https://docs.splunk.com/Documentation/Splunk/8.1.3/Admin/outputsconf

https://docs.splunk.com/Documentation/Forwarder/8.1.3/Forwarder/HowtoforwarddatatoSplunkEnterprise

suggestion, if you have a huge size of eventdata you can think to use 2 hf to use the splunk load-balancing options

 

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
0 Karma

damo66a
Explorer

worked a treat. thanks for your help

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...