Deployment Architecture

How do bundles work with the forwarders?

ddrillic
Ultra Champion

All along we spoke about bundles on the indexers and SHs, but yesterday my colleague mentioned to me that they are used also with the forwarders. I believe the bundles reside at C:\opt\splunk\splunkforwarder\var\run on our windows forwarders.

Any information about it?

Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The bundles sent from search head to indexer are not sent anywhere else.
Search heads do not communicate with forwarders.
Forwarders send data to indexers, but that is not a "bundle".
Deployment Servers (which can be part of an SH instance) communicate with forwarders to tell them which apps to download. These are not "bundles", either.

---
If this reply helps you, Karma would be appreciated.
0 Karma

ddrillic
Ultra Champion

Not sure about the terminology but I see the following -

/monitor/splunkforwarder-linux/var/run/<app>
$ \ls -tlr
total 1252
-rw-------. 1 splunknu dce 1239040 May 16 11:15 Splunk_TA_nix-1558023151.bundle
-rw-------. 1 splunknu dce   40960 Jun 14 09:38 <app>-1560523046.bundle

And by removing this *.bundle file, the deployment server sends a new one.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Those are the apps downloaded by the forwarder from the DS. They're not usually referred to as bundles, but I see that is what the forwarder calls them. Thanks for the education!

---
If this reply helps you, Karma would be appreciated.

ddrillic
Ultra Champion

Thank you @richgalloway for all your help - it was interesting to see these *.bundle files on the forwarder ; -)

0 Karma

ddrillic
Ultra Champion

The following mentions the *.bundle files but not their var/run/<app> location - Extended example: Deploy configurations to several forwarders

In the page, we can search for fwd_to_splunk1-timestamp.bundle.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...