I have successfully setup multiple forwarders to our indexing server "portal03". However, I am now trying to forward from a server (hhwas01) in my system but on a different network that does not have the DNS entry for portal03.
I am able to ping portal03 directly via its IP address from hhwas01, and I am able to ssh over to portal03 using its IP address. I am also able to rsync files from hhwas01 to portal03.
However, when I setup my Splunk forwarder to point to portal03's IP address, the data never arrives at portal03. I have confirmed that my forwarder exists via the Manager-->Forwarding & Receiving-->Configure Forwarding Hosts
Any suggestions on what I may need to do differently? Would this setup require me to send the data via SSH?
http://www.splunk.com/base/Documentation/2.2.6/admin/ForwardingandReceiving#SSH_tips
Thanks in adavance,
Sean