Deployment Architecture

How to troubleshoot forwarder management not showing any clients?

NeedNotToKnow
Explorer

How can I troubleshoot the deployment server or universal or heavy forwarder?

I set up deployment server then in forwarders I run ./splunk set deploy-poll ip:port 

But Forwarder Management clients = 0!

Why? How can I troubleshoot it and solve it?

 

in forwarder:

cat /opt/splunkforwarder/etc/system/local/deploymentclient.conf


[target-broker:deploymentServer]
targetUri = X.X.X.58:8089

 

in deployment-server:

 

/opt/splunk/bin/splunk list deploy-clients


WARNING: Server Certificate Hostname Validation is disabled. Please see server.conf/[sslConfig]/cliVerifyServerName for details.
No deployment clients have contacted this server.

 

Note: the forwarder and deployment server in Google Cloud VMs

Note: I tried it on a local server, and it's running right

 

can anyone help me? 

 
 
 
 
 
 
 
 
 
 
Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Verify the forwarders are allowed to connect to port 8089 on the DS.

Look in splunkd.log on the forwarders for connection/protocol errors.  They'll probably come from the "DC" component.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Verify the forwarders are allowed to connect to port 8089 on the DS.

Look in splunkd.log on the forwarders for connection/protocol errors.  They'll probably come from the "DC" component.

---
If this reply helps you, Karma would be appreciated.

NeedNotToKnow
Explorer

Thank you, the problem is solved

sorry for that, but the firewall was denying 8089.

 
Get Updates on the Splunk Community!

Monitoring MariaDB and MySQL

In a previous post, we explored monitoring PostgreSQL and general best practices around which metrics to ...

Financial Services Industry Use Cases, ITSI Best Practices, and More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Splunk Federated Analytics for Amazon Security Lake

Thursday, November 21, 2024  |  11AM PT / 2PM ET Register Now Join our session to see the technical ...