Deployment Architecture

Deployment Monitor app not showing Forwarders but Deployment Server can see them

fernandoandre
Communicator

We have a server acting only as a Splunk Deployment Server v4.3.2 and we have activated Deployment Monitor v4.3.2. Our problem is that "Deployment Monitor -> Home", "Deployment Monitor -> All Forwarders", etc. doesn't show any data and no Forwarders contacting the Deployment Server.

However, by running "splunk list deploy-clients" the output shows all the splunk UFs we have installed. In fact, we have already deployed several configurations to the UFs and they are sending data to the Indexer (which is not the same server as the Deployment Server).

In Splunk Deployment Server logs we are unable to check anything that shows any clues to us. Does anyone faced this problem before?

Thank you in advance.

0 Karma
1 Solution

fernandoandre
Communicator

Problem solved.

Our approach was wrong. The Deployment Monitor has it's searches/dashboards based on splunk internal's indexes. Universal Forwarders send their own logs to the Indexer, and not to the Deployment Server (obvious!).

Therefore, the solution is to activate the Deployment Monitor on the Indexer instead of doing so in the Deployment Server. The latter will only work for deploying configs and not for monitoring the state of the UFs.

View solution in original post

0 Karma

fernandoandre
Communicator

Problem solved.

Our approach was wrong. The Deployment Monitor has it's searches/dashboards based on splunk internal's indexes. Universal Forwarders send their own logs to the Indexer, and not to the Deployment Server (obvious!).

Therefore, the solution is to activate the Deployment Monitor on the Indexer instead of doing so in the Deployment Server. The latter will only work for deploying configs and not for monitoring the state of the UFs.

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...