Video Series — Splunk Basics (Splunk for Security)
The Intermediate Forwarder (IF)
Video Summary
Welcome back to our Splunk Basics mini-series on Splunk's security solutions, where we showcase some of the fundamental aspects that you are likely to encounter.
In this episode, our technical consultant, Oliver Knapp, delves further into more advanced forwarding concepts, and covers the application and integration of Splunk's Intermediate Forwarder (IF). Sitting in a specific slot within Splunk architecture, the Intermediate Forwarder typically receives data from a Universal Forwarder (UF) and passes it on to a Heavy Forwarder (HF) for further processing. Oliver also explains how Intermediate Forwarders can be used to limit access to certain indexers.





