Deployment Architecture

DS running the Splunk_TA_nix

shpot
New Member

Hi there!   Can a deployment server run the TA *nix?  I also have this TA deploying out to UFs, but lives under $SPLUNK_HOME/etc/deployment-apps.  Is it as simple as copying the Splunk_TA_nix directory from $SPLUNK_HOME/etc/deployment-apps into $SPLUNK_HOME/etc/apps and placing my outputs.conf into $SPLUNK_HOME/etc/system/local ?

Thanks in advance.

Labels (3)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @shpot 

There seems no direct advise from Splunk about TA-nix* on DS however  you can try given if you have few Deployment clients < 50 typically means less busy,  as you mentioned copy from deployment-apps to /apps and configure the outputs.conf under /system/local then restart DS. (outputs.conf should have been already there to forward internal logs of DS, you can verify same with btool command)

Best practice: Install UF on DS host and configure TA under </opt/splunkforwarder>/etc/apps

---------

An upvote would be appreciated if it helps!

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...