Video Series — Splunk Basics (Splunk for Security)

The Intermediate Forwarder (IF)

Video Summary

Welcome back to our Splunk Basics mini-series on Splunk's security solutions, where we showcase some of the fundamental aspects that you are likely to encounter.
In this episode, our technical consultant, Oliver Knapp, delves further into more advanced forwarding concepts, and covers the application and integration of Splunk's Intermediate Forwarder (IF). Sitting in a specific slot within Splunk architecture, the Intermediate Forwarder typically receives data from a Universal Forwarder (UF) and passes it on to a Heavy Forwarder (HF) for further processing. Oliver also explains how Intermediate Forwarders can be used to limit access to certain indexers.

Other Videos You Might Like

Splunk Basics - Forwarding HFUF
Splunk for Security Architecting Streaming - Episode 4
Splunk for Security Stream Data-Flows - Episode 5

Get in Touch to Learn More

Would you like to build your knowledge further?
Scroll to Top