Splunk Cloud Platform

Splunk Heavy Forwarded to Splunk Cloud?

JohnACERTUS
Explorer

Am I going crazy or is there legit not documentation on setting up a HF to point and send data to our cloud instance?  

 

All the documentation I am finding is centered around a 100% on-prem setup.  

 

Anyone have any luck with this?

Labels (1)

JohnACERTUS
Explorer

I've done this 

"If you want to set up a heavy forwarder to send data in Splunk Cloud, request a deployment server license from Splunk support to allow them to carry out functions above and beyond what is covered by the forwarder license. See Data collection in the Splunk Cloud Service Description."

On the data collection link, can you point to me where it specifies? 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Follow the instructions in the second link provided.

---
If this reply helps you, Karma would be appreciated.
0 Karma

JohnACERTUS
Explorer

Maybe I'm still missing something but i've read over that documentation and noticed that it still doesn't specify how to forward logs from HF to splunk cloud.  One notable thing is it doesn't say what the URL:PORT to use...  

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's documented.  See https://docs.splunk.com/Documentation/SplunkCloud/8.1.2101/Data/UsingforwardingagentsCloud or https://docs.splunk.com/Documentation/Forwarder/latest/Forwarder/HowtoforwarddatatoSplunkCloud

You also can go to the "Universal Forwarder" app in your Splunk Cloud instance for instructions.

---
If this reply helps you, Karma would be appreciated.
0 Karma

JohnACERTUS
Explorer
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk is a very Linux-centric company so Windows-oriented instructions are not as common as they could be. Most of the time, all a Windows admin needs to do is change file path delimiters, but every now and then a Linux command has to be replaced with a Windows equivalent.  

In this case, I use 7-zip in place of tar.  Also, Ubuntu on Windows has tar available.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...