Deployment Architecture

DS running the Splunk_TA_nix

shpot
New Member

Hi there!   Can a deployment server run the TA *nix?  I also have this TA deploying out to UFs, but lives under $SPLUNK_HOME/etc/deployment-apps.  Is it as simple as copying the Splunk_TA_nix directory from $SPLUNK_HOME/etc/deployment-apps into $SPLUNK_HOME/etc/apps and placing my outputs.conf into $SPLUNK_HOME/etc/system/local ?

Thanks in advance.

Labels (3)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @shpot 

There seems no direct advise from Splunk about TA-nix* on DS however  you can try given if you have few Deployment clients < 50 typically means less busy,  as you mentioned copy from deployment-apps to /apps and configure the outputs.conf under /system/local then restart DS. (outputs.conf should have been already there to forward internal logs of DS, you can verify same with btool command)

Best practice: Install UF on DS host and configure TA under </opt/splunkforwarder>/etc/apps

---------

An upvote would be appreciated if it helps!

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...