I may have missed a topic in my search but is there a way to do the following (im also fairly new to Splunk so be gentle 😁 )
We have a server locked down on our network and has no outside access but we can configure internal (server to server) access.
Is there a way to use a Universal Forwarder on that server to forward to the local on prem Heavy Forwarder and then relay those to our Splunk Cloud?
Thanks in advance
Hello @damo66a again,
yes you can configure the uf to send to HF and in the end at splunkcloud
be careful to to configure your outputs.conf
https://docs.splunk.com/Documentation/Splunk/8.1.3/Admin/outputsconf
https://docs.splunk.com/Documentation/Forwarder/8.1.3/Forwarder/HowtoforwarddatatoSplunkEnterprise
suggestion, if you have a huge size of eventdata you can think to use 2 hf to use the splunk load-balancing options
Hello @damo66a again,
yes you can configure the uf to send to HF and in the end at splunkcloud
be careful to to configure your outputs.conf
https://docs.splunk.com/Documentation/Splunk/8.1.3/Admin/outputsconf
https://docs.splunk.com/Documentation/Forwarder/8.1.3/Forwarder/HowtoforwarddatatoSplunkEnterprise
suggestion, if you have a huge size of eventdata you can think to use 2 hf to use the splunk load-balancing options
worked a treat. thanks for your help