Deployment Architecture

Deployment server firewall rules

EricPartington
Communicator

I am planning to use the deployment server functionality of splunk 4.2 . I am trying to in down all the firewall rules and direction that will be required to make all the components of splunk work.

is the deployment server a push from server to client, or are there client to server initiated communications (call home, checkups)? Do these use the same 8089 (or configured) port that a distributed search head and indexer would use to communicate ?

what about the master license server? What ports does it use to transfer/poll for licensing information? What is the direction of that network flow ? (pull from master or push from slave?)

1 Solution

hazekamp
Builder

With respect to deployment client-server, the client is responsible for contacting the server. The port for this is configurable based on splunkd of your deployment server but would default to 8089.

See also: http://www.splunk.com/base/Documentation/latest/Deploy/Aboutdeploymentserver

With respect to License slaves I believe they work similar to deployment clients (contacting License master via splunkd 8089 by default).

See also: http://www.splunk.com/base/Documentation/latest/Admin/Configurealicenseslave

View solution in original post

hazekamp
Builder

With respect to deployment client-server, the client is responsible for contacting the server. The port for this is configurable based on splunkd of your deployment server but would default to 8089.

See also: http://www.splunk.com/base/Documentation/latest/Deploy/Aboutdeploymentserver

With respect to License slaves I believe they work similar to deployment clients (contacting License master via splunkd 8089 by default).

See also: http://www.splunk.com/base/Documentation/latest/Admin/Configurealicenseslave

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...