Deployment Architecture

How do you add additional deployed forwarders to existing server classes?

systemsadminist
Explorer

I have a server class called DomainControllers, and have 2 existing DCs that were added when I initially created the server class. I would like to simply add additional DCs to that server class, and I can't seem to find a quick way of doing so.

You would think it would be the same process as adding/removing when creating the server class in the beginning..

But no..

Tags (1)
0 Karma
1 Solution

adonio
Ultra Champion

why isnt it?
add deploymentclient.conf to your new DC forwarder, make sure ou can see it in forwarder management page in splunk DS gui, pick the correct serverclass, click edit, add clients, add the new forwarder, save, thats it

View solution in original post

0 Karma

adonio
Ultra Champion

why isnt it?
add deploymentclient.conf to your new DC forwarder, make sure ou can see it in forwarder management page in splunk DS gui, pick the correct serverclass, click edit, add clients, add the new forwarder, save, thats it

0 Karma

systemsadminist
Explorer

This is all in Splunk Cloud currently. So it is slightly different. However, you knocked a screw around and I was able to find the equivalent in the Cloud side of the mix.

Thanks for the help.

0 Karma

adonio
Ultra Champion

can you share in an answer what you have done and mark your question as answered?
also up vote any comment that helped.
happy its been resolved

0 Karma

systemsadminist
Explorer

No problem. I awarded you the points above since it is the correct way for Splunk On-Prem / Enterprise. As far as Splunk Cloud goes, an admin would need to go to:

Settings -> Forwarder Management -> Choose Server Classes -> Edit -> Edit Clients

A new window refreshes showing all existing clients/forwarders, and a Include (whitelist) field at the very top. Simply add in the name of the additional forward from the list and hit Save.

Thanks again

Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...