<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to set up a heavy forwarder/deployment server on one server? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-a-heavy-forwarder-deployment-server-on-one-server/m-p/250955#M48309</link>
    <description>&lt;P&gt;I do not see any data coming into our indexers when this is set however, i do see the UF's getting the deployment app that points them to the HF's.&lt;/P&gt;

&lt;P&gt;When i change the app to send to the indexers to bypass the HF's i see all the data. I don't understand if the HF needs any addition stanzas set to listen for these connections?&lt;/P&gt;</description>
    <pubDate>Thu, 28 Jan 2016 21:16:42 GMT</pubDate>
    <dc:creator>sbattista09</dc:creator>
    <dc:date>2016-01-28T21:16:42Z</dc:date>
    <item>
      <title>How to set up a heavy forwarder/deployment server on one server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-a-heavy-forwarder-deployment-server-on-one-server/m-p/250952#M48306</link>
      <description>&lt;P&gt;After building a deployment and a heavy forwarder on one server we seem to be having issues when we point the universal forwarders to the heavy forwarder. We are new to Splunk 6.3.1 and are not sure if there have been any changes in how to do this?&lt;/P&gt;

&lt;P&gt;Overview:&lt;BR /&gt;
We spun up two new Splunk heavy forwarders for a new company and need both of them to forward logs to our indexers. One of the new heavy forwarders will also act as a deployment server. When setting them up, my stanza are as follows;&lt;/P&gt;

&lt;P&gt;Deployment app in &lt;CODE&gt;Splunk\etc\deployment-apps\App1\default&lt;/CODE&gt; (outputs.conf)-&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
defaultGroup = lb_group
disabled = false
heartbeatFrequency = 300


[tcpout:lb_group]
server = HF1.com:9997, HF2.com:9997
autoLB = true
disabled = false
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;HF config: &lt;CODE&gt;Splunk\etc\system\local&lt;/CODE&gt; (outputs.conf)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[syslog:my_syslog_group]
#FWD logs to an IDS
disabled = false
server = 10.10.10.10:514
type = udp
sendCookedData = false

[tcpout]
defaultGroup = lb_group
disabled = false

[tcpout:lb_group]
server = idx01.com:9997, idx02.com:9997, idx03.com:9997 
autoLB = true
disabled = false
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any input will help,&lt;BR /&gt;
thank you in advance! &lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2016 19:52:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-a-heavy-forwarder-deployment-server-on-one-server/m-p/250952#M48306</guid>
      <dc:creator>sbattista09</dc:creator>
      <dc:date>2016-01-28T19:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up a heavy forwarder/deployment server on one server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-a-heavy-forwarder-deployment-server-on-one-server/m-p/250953#M48307</link>
      <description>&lt;P&gt;This should work. Just note that the HF that runs as the DS cannot be a member of itself. So you will only be able to deploy the config to one of the HFs, not both.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2016 20:02:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-a-heavy-forwarder-deployment-server-on-one-server/m-p/250953#M48307</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2016-01-28T20:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up a heavy forwarder/deployment server on one server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-a-heavy-forwarder-deployment-server-on-one-server/m-p/250954#M48308</link>
      <description>&lt;P&gt;What problem do you see when your UF are pointing to HF?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2016 20:08:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-a-heavy-forwarder-deployment-server-on-one-server/m-p/250954#M48308</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-01-28T20:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up a heavy forwarder/deployment server on one server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-a-heavy-forwarder-deployment-server-on-one-server/m-p/250955#M48309</link>
      <description>&lt;P&gt;I do not see any data coming into our indexers when this is set however, i do see the UF's getting the deployment app that points them to the HF's.&lt;/P&gt;

&lt;P&gt;When i change the app to send to the indexers to bypass the HF's i see all the data. I don't understand if the HF needs any addition stanzas set to listen for these connections?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2016 21:16:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-a-heavy-forwarder-deployment-server-on-one-server/m-p/250955#M48309</guid>
      <dc:creator>sbattista09</dc:creator>
      <dc:date>2016-01-28T21:16:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up a heavy forwarder/deployment server on one server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-a-heavy-forwarder-deployment-server-on-one-server/m-p/250956#M48310</link>
      <description>&lt;P&gt;Check if this is been set on HF&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Set up receiving with the configuration file
You can enable receiving on your Splunk Enterprise instance by configuring inputs.conf in $SPLUNK_HOME/etc/system/local. To configure a universal forwarder as an intermediate forwarder (a forwarder that functions also as a receiver), use this method.

To enable receiving, add a [splunktcp] stanza that specifies the receiving port. In this example, the receiving port is 9997:

[splunktcp://9997]
disabled = 0
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 28 Jan 2016 21:39:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-a-heavy-forwarder-deployment-server-on-one-server/m-p/250956#M48310</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-01-28T21:39:38Z</dc:date>
    </item>
  </channel>
</rss>

