All Apps and Add-ons

Can the Splunk for Asset Discovery app be installed on a Universal Forwarder?

msudhindra
Path Finder

Can the Splunk for Asset Discovery app be installed on a Universal Forwarder ?

I would like a Universal Forwarder system be the one that scans all the IP address ranges for availability, and then send the information to the indexers.

I can install nmap on my forwarder and that should not be an issue. Also, the app can be pushed out in its fully configured state using the Deployment Server, so the lack of a GUI on the forwarder should not hinder the deployment either.

Any help here would be greatly appreciated.

Thanks and Regards,
Madan

0 Karma
1 Solution

mw
Splunk Employee
Splunk Employee

Yes, it's designed to be used from a UF. As you said, you'll want to deploy nmap, and the app can be configured and deployed via DS as normal. The included scripted inputs can be configured to scan whatever IP range you'd like, but by default (i.e. with no target provided) they'll figure out what subnet(s) they're on and scan those. Due to that, you can easily deploy the app to each subnet and scan all in parallel, very quickly.

View solution in original post

mw
Splunk Employee
Splunk Employee

Yes, it's designed to be used from a UF. As you said, you'll want to deploy nmap, and the app can be configured and deployed via DS as normal. The included scripted inputs can be configured to scan whatever IP range you'd like, but by default (i.e. with no target provided) they'll figure out what subnet(s) they're on and scan those. Due to that, you can easily deploy the app to each subnet and scan all in parallel, very quickly.

msudhindra
Path Finder

Thanks a lot !

I'll get started on configuring this

0 Karma
Get Updates on the Splunk Community!

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...