Getting Data In

Getting Data to Splunk from clients outside our LAN

mmeredith
New Member

I am trying to setup our Splunk architecture to be able to receive events from clients/workstations outside our local network. The simplest solution is just making the main indexer externally accessible, but we don't want to do that. Is there a way to setup a Heavy Forwarder like a proxy to receive events from external clients and then send them to the main indexer? I haven't been able to find anything related to this when I try to research.

Thanks.

Labels (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, you could set up a HF and make it accessible to external clients.  This is a common way to handle situations like this.  The HF is like a DMZ in that outsiders can connect to it, but the network only allows traffic from the HF to reach the indexers.

BTW, there's no such thing as a "main indexer" in Splunk.  Indexers are referred to as "search peers" because they're all equal.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...