Getting Data In

Can a universal forwarder work without connectivity to a deployment server?

eastlandm
New Member

We have universal forwarders planned for the DMZ. Firewall admins want to limit connectivity to as few ports as possible.

I know the UF needs to connect to the indexer (TCP-9997), but can it live without communicating to the deployment server (TCP-8089)?

No apps are required, and I plan on just configuring inputs.conf directly as only logfile & perfmon counters are required.

So questions needing answers:
1. Will the UF start up and operate if it can't communicate with the deployment server?
2. Is there any configuration required to be done to allow UF to operate without access to a deployment server?

I've looked at an intermediate forwarder, but f/w admins don't like dmz hosts talking to each other, so that option is out.

0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

You UF / HF can work without a deployment server. In your case, since these are in a DMZ without connectivity to the deployment server (DS), you should just configure these without a DS. Then configure your inputs manually and distribute them to these hosts.

Even if they did connect to a DS, and then loose connectivity, they will still function. The only issues arise when they reconnect to the DS, if apps are not the same, the client will redeploy and download all apps again.

So;
1) Yes
2) No

View solution in original post

esix_splunk
Splunk Employee
Splunk Employee

You UF / HF can work without a deployment server. In your case, since these are in a DMZ without connectivity to the deployment server (DS), you should just configure these without a DS. Then configure your inputs manually and distribute them to these hosts.

Even if they did connect to a DS, and then loose connectivity, they will still function. The only issues arise when they reconnect to the DS, if apps are not the same, the client will redeploy and download all apps again.

So;
1) Yes
2) No

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...