Deployment Architecture

Push apps from deployment server automatically to universal forwarders when they connect

vikram_m
Path Finder

I have an app created and deployment client created.

I need to push the app automatically to the UFs which are connected. How can that be achieved?

For now UFs are connected to deployment server from there I add them in server class and push app. I want outputs.conf app should be automatically pushed to them.

Please help.

Thanks.
Vikram.

0 Karma

amahoski
Explorer

If you want to push outputs.conf itself see below:

you can use this link to be aware of .conf file precedence to accomplish this:

http://docs.splunk.com/Documentation/Splunk/6.6.3/Admin/Wheretofindtheconfigurationfiles

Create an app with an outputs.conf and push it out to the forwarder. The deployment server should find that the app has been created and automatically push it as long as the server has been added as a client machine to the server class itself.

Note that the system/local directory takes priority so you must ensure that the properties in system/local are not already utilized otherwise, it won't take precedence.

0 Karma

vikram_m
Path Finder

This was helpful amahoski but what I would like to know is, as I want to push outputs.conf automatically to the UFs, how can I achieve this functionality.

0 Karma

amahoski
Explorer

Can you provide more clarity on this? Forwarder management is just one methodology for managing forwarders. Adding apps to the server class is the "out of the box" method provided by splunk to add apps to remote universal forwarders.

Do you want to push the outputs.conf file itself to the forwarder?

If so, you can use this link to accomplish this:

http://docs.splunk.com/Documentation/Splunk/6.6.3/Admin/Wheretofindtheconfigurationfiles

Create an app with an outputs.conf and push it out to the forwarder. Note that the system/local directory takes priority so you must ensure that the properties in system/local are not already utilized otherwise, it won't take precedence.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...