All Apps and Add-ons

Universal Forwarder does not download app

SplunkExplorer
Contributor

Hi Splunkers, I have a strange situation about a some universal forwarders.

On some Windows host, a colleague has installed the UF using the graphical wizards.
Those forwarders must be managed with a Deployment server.
He has NOT used the "customize" options; so, he has not set which logs must be sent to HF (Application, Security and so on) and a destination HF/Indexers. He has only inserted:

  • Admin username and password
  • Deployment server IP address and port

As wrote above, he didn't inserted HF and/or Indexers; the idea is that once the UF has spoken with the Deployment server, 2 apps that contains inputs.conf and outputs.conf are downloaded and, after that, logs are sent.
On Deployment server (we checked), the apps that should to be downloaded form UF have been created and contains the above 2 files.

So, why I wrote "the apps that should be downloaded?" Well, due logs are not collected and sent to HF, we performed some troubleshoot and we found that apps has not been downloaded. 
I mean: on host where UF is installed, if we go on $SplunkUFHOME$\etc\apps, the 2 apps are not present.
So, that means that no custom inputs.conf and outputs.conf are present on UF. Only the default provided with installation are present.

First thing we thought: ok, we have network issues. But it seems not: we are perfectly able, from host with UF, to ping and telnet deployment server on its port. At same time, we can access firewall that manage this traffic and we don't see, on firewall logs, any evidence of blocked/truncated connections. UF can reach DS and vice versa without issues.

We tried so to manually copy folders with apps inside UF (I know, very bad things, don't blame me please...) but the situation is always the same.

So, the question is: if no network issues are present, what can be the root cause about no downloaded apps?

 

Labels (3)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @SplunkExplorer,

I suppose that you followed all the steps of Deployment Server configuration, anyway the issue usually are related to:

  • the insertion of the new UF un a ServerClass containing the apps to deploy,
  • the rights on the app.

I suppose that you already checked the connection between the UF and the DS on the 8089 port.

In addition I usually follow tis approach:

  • I create an add on containing only deploymentclient.conf addressing the DS,
  • then I create a ServerClass where all the UF are present (* in whitelist), with associated the above add on,
  • I check the connection on port 8089,
  • then I manually copy the add on on the UF, so the UF can connect to the DS.

Ciao.

Guseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @SplunkExplorer,

I suppose that you followed all the steps of Deployment Server configuration, anyway the issue usually are related to:

  • the insertion of the new UF un a ServerClass containing the apps to deploy,
  • the rights on the app.

I suppose that you already checked the connection between the UF and the DS on the 8089 port.

In addition I usually follow tis approach:

  • I create an add on containing only deploymentclient.conf addressing the DS,
  • then I create a ServerClass where all the UF are present (* in whitelist), with associated the above add on,
  • I check the connection on port 8089,
  • then I manually copy the add on on the UF, so the UF can connect to the DS.

Ciao.

Guseppe

SplunkExplorer
Contributor

Hi @gcusello , thanks for your help, fast and detailed as usual.

You are right: the Deployment server is well configured, also because it is not a "new" one but a prod host that, before windows clients I mentioned in post opening, has been used to manage other hosts.
And yes: when I checked connection between UF and DS and I found that everything is ok, I checked on DS port 8089.

I'm going to follow your suggestion and update once performed.

Luca

0 Karma
Get Updates on the Splunk Community!

Uncovering Multi-Account Fraud with Splunk Banking Analytics

Last month, I met with a Senior Fraud Analyst at a nationally recognized bank to discuss their recent success ...

Secure Your Future: A Deep Dive into the Compliance and Security Enhancements for the ...

What has been announced?  In the blog, “Preparing your Splunk Environment for OpensSSL3,”we announced the ...

New This Month in Splunk Observability Cloud - Synthetic Monitoring updates, UI ...

This month, we’re delivering several platform, infrastructure, application and digital experience monitoring ...