Deployment Architecture

How to troubleshoot forwarder management not showing any clients?

NeedNotToKnow
Explorer

How can I troubleshoot the deployment server or universal or heavy forwarder?

I set up deployment server then in forwarders I run ./splunk set deploy-poll ip:port 

But Forwarder Management clients = 0!

Why? How can I troubleshoot it and solve it?

 

in forwarder:

cat /opt/splunkforwarder/etc/system/local/deploymentclient.conf


[target-broker:deploymentServer]
targetUri = X.X.X.58:8089

 

in deployment-server:

 

/opt/splunk/bin/splunk list deploy-clients


WARNING: Server Certificate Hostname Validation is disabled. Please see server.conf/[sslConfig]/cliVerifyServerName for details.
No deployment clients have contacted this server.

 

Note: the forwarder and deployment server in Google Cloud VMs

Note: I tried it on a local server, and it's running right

 

can anyone help me? 

 
 
 
 
 
 
 
 
 
 
Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Verify the forwarders are allowed to connect to port 8089 on the DS.

Look in splunkd.log on the forwarders for connection/protocol errors.  They'll probably come from the "DC" component.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Verify the forwarders are allowed to connect to port 8089 on the DS.

Look in splunkd.log on the forwarders for connection/protocol errors.  They'll probably come from the "DC" component.

---
If this reply helps you, Karma would be appreciated.

NeedNotToKnow
Explorer

Thank you, the problem is solved

sorry for that, but the firewall was denying 8089.

 
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...