Getting Data In

Can a universal forwarder work without connectivity to a deployment server?

eastlandm
New Member

We have universal forwarders planned for the DMZ. Firewall admins want to limit connectivity to as few ports as possible.

I know the UF needs to connect to the indexer (TCP-9997), but can it live without communicating to the deployment server (TCP-8089)?

No apps are required, and I plan on just configuring inputs.conf directly as only logfile & perfmon counters are required.

So questions needing answers:
1. Will the UF start up and operate if it can't communicate with the deployment server?
2. Is there any configuration required to be done to allow UF to operate without access to a deployment server?

I've looked at an intermediate forwarder, but f/w admins don't like dmz hosts talking to each other, so that option is out.

0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

You UF / HF can work without a deployment server. In your case, since these are in a DMZ without connectivity to the deployment server (DS), you should just configure these without a DS. Then configure your inputs manually and distribute them to these hosts.

Even if they did connect to a DS, and then loose connectivity, they will still function. The only issues arise when they reconnect to the DS, if apps are not the same, the client will redeploy and download all apps again.

So;
1) Yes
2) No

View solution in original post

esix_splunk
Splunk Employee
Splunk Employee

You UF / HF can work without a deployment server. In your case, since these are in a DMZ without connectivity to the deployment server (DS), you should just configure these without a DS. Then configure your inputs manually and distribute them to these hosts.

Even if they did connect to a DS, and then loose connectivity, they will still function. The only issues arise when they reconnect to the DS, if apps are not the same, the client will redeploy and download all apps again.

So;
1) Yes
2) No

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...