Deployment Architecture

DS running the Splunk_TA_nix

shpot
New Member

Hi there!   Can a deployment server run the TA *nix?  I also have this TA deploying out to UFs, but lives under $SPLUNK_HOME/etc/deployment-apps.  Is it as simple as copying the Splunk_TA_nix directory from $SPLUNK_HOME/etc/deployment-apps into $SPLUNK_HOME/etc/apps and placing my outputs.conf into $SPLUNK_HOME/etc/system/local ?

Thanks in advance.

Labels (3)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @shpot 

There seems no direct advise from Splunk about TA-nix* on DS however  you can try given if you have few Deployment clients < 50 typically means less busy,  as you mentioned copy from deployment-apps to /apps and configure the outputs.conf under /system/local then restart DS. (outputs.conf should have been already there to forward internal logs of DS, you can verify same with btool command)

Best practice: Install UF on DS host and configure TA under </opt/splunkforwarder>/etc/apps

---------

An upvote would be appreciated if it helps!

0 Karma
Get Updates on the Splunk Community!

Splunk Lantern | Spotlight on Security: Adoption Motions, War Stories, and More

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...

Tech Talk | One Log to Rule Them All

One log to rule them all: how you can centralize your troubleshooting with Splunk logs We know how important ...