All Apps and Add-ons

Can the Splunk for Asset Discovery app be installed on a Universal Forwarder?

msudhindra
Path Finder

Can the Splunk for Asset Discovery app be installed on a Universal Forwarder ?

I would like a Universal Forwarder system be the one that scans all the IP address ranges for availability, and then send the information to the indexers.

I can install nmap on my forwarder and that should not be an issue. Also, the app can be pushed out in its fully configured state using the Deployment Server, so the lack of a GUI on the forwarder should not hinder the deployment either.

Any help here would be greatly appreciated.

Thanks and Regards,
Madan

0 Karma
1 Solution

mw
Splunk Employee
Splunk Employee

Yes, it's designed to be used from a UF. As you said, you'll want to deploy nmap, and the app can be configured and deployed via DS as normal. The included scripted inputs can be configured to scan whatever IP range you'd like, but by default (i.e. with no target provided) they'll figure out what subnet(s) they're on and scan those. Due to that, you can easily deploy the app to each subnet and scan all in parallel, very quickly.

View solution in original post

mw
Splunk Employee
Splunk Employee

Yes, it's designed to be used from a UF. As you said, you'll want to deploy nmap, and the app can be configured and deployed via DS as normal. The included scripted inputs can be configured to scan whatever IP range you'd like, but by default (i.e. with no target provided) they'll figure out what subnet(s) they're on and scan those. Due to that, you can easily deploy the app to each subnet and scan all in parallel, very quickly.

View solution in original post

msudhindra
Path Finder

Thanks a lot !

I'll get started on configuring this

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!