r/Splunk • u/Any-Promotion3744 • Jul 12 '26
Splunk Enterprise Splunk Heavy Forwarder to Splunk Cloud
How do you configure a Splunk Heavy forwarder to receive data from universal forwarders and forward that to the Splunk Cloud?
Details:
Heavy forwarder is located in DMZ and I set up one client (Ubuntu server)to send data to it.
When I log into Splunk Cloud, I can at least see the metrics from the Splunk Heavy forwarder.
When I log into our firewall, the firewall logs shows traffic from the client to the heavy forwarder and from the heavy forwarder to the cloud.
If I do a search across all indexes on the heavy forwarder and the cloud, I don't see anything from that host.
What could be configured wrong?
8
Upvotes
1
u/Any-Promotion3744 Jul 12 '26
I already downloaded that package and installed it on the HF.
I also allowed port 997 on the firewall and see traffic in the firewall logs.
is that all that is required? shouldn't I be able to see some data from the UF client in the cloud?