Deployment Architecture

DS running the Splunk_TA_nix

shpot
New Member

Hi there!   Can a deployment server run the TA *nix?  I also have this TA deploying out to UFs, but lives under $SPLUNK_HOME/etc/deployment-apps.  Is it as simple as copying the Splunk_TA_nix directory from $SPLUNK_HOME/etc/deployment-apps into $SPLUNK_HOME/etc/apps and placing my outputs.conf into $SPLUNK_HOME/etc/system/local ?

Thanks in advance.

Labels (3)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @shpot 

There seems no direct advise from Splunk about TA-nix* on DS however  you can try given if you have few Deployment clients < 50 typically means less busy,  as you mentioned copy from deployment-apps to /apps and configure the outputs.conf under /system/local then restart DS. (outputs.conf should have been already there to forward internal logs of DS, you can verify same with btool command)

Best practice: Install UF on DS host and configure TA under </opt/splunkforwarder>/etc/apps

---------

An upvote would be appreciated if it helps!

0 Karma
Get Updates on the Splunk Community!

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...

Admin Console: A Single, Unified Interface for All Your Cloud Admin Needs

WATCH NOWJoin us to learn how the admin console can save you time and give you more control over the Splunk® ...