Deployment Architecture

How to edit the configuration for my Search Head to act as a Deployment Server?

nce054
Path Finder

I am trying to configure my Search Head to act as a Deployment Server for my Universal Forwarders. On the forwarders, I have put the following in $SPLUNK_HOME\etc\system\local\deploymentclient.conf :

 [deployment-client]
    clientName = Evan-Test
  [target-broker:deploymentServer]
    targetUri= host:port

Where host:port is my Search Head. What do I need to change on the Search Head for it to start acting as a Deployment Server? I go to Settings->Server Settings->Deployment Client, and I see no clients hooked up to my Search Head/Deployment Server.

0 Karma
1 Solution

woodcock
Esteemed Legend

The simplest way is to use the GUI and go to Settings -> Forwarder Management -> Server Classes -> Create One.

View solution in original post

0 Karma

woodcock
Esteemed Legend

The simplest way is to use the GUI and go to Settings -> Forwarder Management -> Server Classes -> Create One.

0 Karma

nce054
Path Finder

Thank you!

0 Karma

woodcock
Esteemed Legend

The serverclass lets you specify whitelist and blacklist for incoming connections. Without one of these set, your Search Head is not a DS.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...