Deployment Architecture

Is there a limit to the amount of servers a deployment server can black/whitelist?

jcgever
Explorer

We are in the middle of trying to split the stream of data between splunk and a third party. In order to do this we are going to have to push out a custom universal forwarder to about 1000 servers and black list them in a server group on the deployment server. Is there a limit to the amount of server names that we can blacklist?

Tags (1)
0 Karma

saramamurthy_sp
Splunk Employee
Splunk Employee

I don't see the point in the way you are trying to achieve this, having said that with respect to your question of the limits.
Well, there is no limitation in which we can blacklist/whitelist the server and you can add n number of the server names in these filtering fields.

To have a better understanding of these two, I would suggest you to check the below link.

DOC: https://docs.splunk.com/Documentation/Splunk/7.3.2/Updating/Filterclients#Define_filters_through_ser....
https://docs.splunk.com/Documentation/SplunkCloud/7.2.7/Data/Whitelistorblacklistspecificincomingdat....

I would still suggest you to cross-check your implementation.

0 Karma

adonio
Ultra Champion

Hello there,

First, i think there is no limit and you should be fine.
However, not sure why will you choose this strategy. why not create 2 different inclusive serverclasses?

woodcock
Esteemed Legend

I agree with this.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...