Getting Data In

Configure a Splunk Deployment Manager

qazwsxedc994
Explorer

So far I have an Fowarder feeding data into my Indexer where I have a search head setup to search the indexes. If i wanted to set up a Deployment Manager to look after my indexer and search head how would i go about configuring this setup?? Im so lost and confused right now.

0 Karma

koshyk
Super Champion

It is straightforward. You just need to provide your "Splunk forwarder" file:

${SPLUNK_FWD_HOME}/etc/apps/deployclient/local/deploymentclient.conf

with below entry

[deployment-client]
[target-broker:deploymentServer]
targetUri = <DEPLOY_SERVER>

I've automated installation of Splunk Forwarder in Windows/Linux. Code can be found here

0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...