Deployment Architecture

DS running the Splunk_TA_nix

shpot
New Member

Hi there!   Can a deployment server run the TA *nix?  I also have this TA deploying out to UFs, but lives under $SPLUNK_HOME/etc/deployment-apps.  Is it as simple as copying the Splunk_TA_nix directory from $SPLUNK_HOME/etc/deployment-apps into $SPLUNK_HOME/etc/apps and placing my outputs.conf into $SPLUNK_HOME/etc/system/local ?

Thanks in advance.

Labels (3)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @shpot 

There seems no direct advise from Splunk about TA-nix* on DS however  you can try given if you have few Deployment clients < 50 typically means less busy,  as you mentioned copy from deployment-apps to /apps and configure the outputs.conf under /system/local then restart DS. (outputs.conf should have been already there to forward internal logs of DS, you can verify same with btool command)

Best practice: Install UF on DS host and configure TA under </opt/splunkforwarder>/etc/apps

---------

An upvote would be appreciated if it helps!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...