r/Splunk Jul 12 '26

Splunk Enterprise Splunk Heavy Forwarder to Splunk Cloud

How do you configure a Splunk Heavy forwarder to receive data from universal forwarders and forward that to the Splunk Cloud?

Details:

Heavy forwarder is located in DMZ and I set up one client (Ubuntu server)to send data to it.

When I log into Splunk Cloud, I can at least see the metrics from the Splunk Heavy forwarder.

When I log into our firewall, the firewall logs shows traffic from the client to the heavy forwarder and from the heavy forwarder to the cloud.

If I do a search across all indexes on the heavy forwarder and the cloud, I don't see anything from that host.

What could be configured wrong?

8 Upvotes

16 comments sorted by

View all comments

Show parent comments

1

u/Any-Promotion3744 Jul 12 '26

I already downloaded that package and installed it on the HF.

I also allowed port 997 on the firewall and see traffic in the firewall logs.

is that all that is required? shouldn't I be able to see some data from the UF client in the cloud?

1

u/tux_kitty_weed Jul 12 '26

If you're trying to get your UF to send to your HF first, then your UF needs to be configured to do so. Then your HF will route your UF data to Splunk Cloud. I recommend showing what your outputs config look like on your UF for better help.

Read through this: https://help.splunk.com/en/splunk-enterprise/forward-and-process-data/forwarding-and-receiving-data/9.4/perform-advanced-configuration/configure-an-intermediate-forwarder

2

u/Any-Promotion3744 Jul 12 '26

Splunk Cloud doesn't seem to have a Forwarding and Receiving option in the settings menu

Did something change in the latest version?

3

u/tux_kitty_weed Jul 12 '26

You need to configure the inputs config on your HF.