Splunkforwarder HEC input/output to another splunkforwarder

New Member


i'm triing to use an UF to forward HEC from internet data to another UF in our DMZ

look like :

httplistner input (UF1) httpout output  --> httplistner input (UF2 in DMZ) S2S output --> Splunk enterprise in lan

if i curl both of http listener i got success, 

curl -k -u "x:TOKEN" "https://UF1:8088/services/collector/event" -d '{"event": "Hello, world!"}'

curl -k -u "x:TOKEN" "https://UF2:8088/services/collector/event" -d '{"event": "Hello, world!"}'

But i got events in my splunk indexeur only on the second curl, the first one look like the output never forward to the UF2... 

Nothing in both uf1-2 logs about errors. 

My /opt/splunkforwarder/etc/system/local/outputs.conf on UF1 look like:

defaultGroup = default-autolb-group
disabled = 1

disabled = 0
httpEventCollectorToken = MYTOKEN
uri = https://UF2-IP:8088
batchSize = 65536
batchTimeout = 5


Thks for help !!

Flo V.

Labels (1)
0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!