Getting Data In

Can a universal forwarder work without connectivity to a deployment server?

eastlandm
New Member

We have universal forwarders planned for the DMZ. Firewall admins want to limit connectivity to as few ports as possible.

I know the UF needs to connect to the indexer (TCP-9997), but can it live without communicating to the deployment server (TCP-8089)?

No apps are required, and I plan on just configuring inputs.conf directly as only logfile & perfmon counters are required.

So questions needing answers:
1. Will the UF start up and operate if it can't communicate with the deployment server?
2. Is there any configuration required to be done to allow UF to operate without access to a deployment server?

I've looked at an intermediate forwarder, but f/w admins don't like dmz hosts talking to each other, so that option is out.

0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

You UF / HF can work without a deployment server. In your case, since these are in a DMZ without connectivity to the deployment server (DS), you should just configure these without a DS. Then configure your inputs manually and distribute them to these hosts.

Even if they did connect to a DS, and then loose connectivity, they will still function. The only issues arise when they reconnect to the DS, if apps are not the same, the client will redeploy and download all apps again.

So;
1) Yes
2) No

View solution in original post

esix_splunk
Splunk Employee
Splunk Employee

You UF / HF can work without a deployment server. In your case, since these are in a DMZ without connectivity to the deployment server (DS), you should just configure these without a DS. Then configure your inputs manually and distribute them to these hosts.

Even if they did connect to a DS, and then loose connectivity, they will still function. The only issues arise when they reconnect to the DS, if apps are not the same, the client will redeploy and download all apps again.

So;
1) Yes
2) No

Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...