Getting Data In

Deployment server and Universal Forwarder

ciandro84
Engager

Does the deployment server come with a universal forwarder of its own already installed on it?
I have a central indexer and on another server I have the deployment server setup.

Is there a universal forwarder installed on the deployment server so that it can log data about that server to my central indexer?

Thanks!

0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Actually Deployment Server is just a variant configuration of the standard Splunk Enterprise installation. You can configure it to operate as both a Deployment Server and a Splunk Light Forwarder. A Light Forwarder functions and is configured substantially identically to a Universal Forwarder, though the setup and installation is slightly different.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

Actually Deployment Server is just a variant configuration of the standard Splunk Enterprise installation. You can configure it to operate as both a Deployment Server and a Splunk Light Forwarder. A Light Forwarder functions and is configured substantially identically to a Universal Forwarder, though the setup and installation is slightly different.

lguinn2
Legend

Just install Splunk on the box that will be the deployment server. Then go into the Manager and look for Forwarding and Receiving. Set the forwarding options. BTW, if you set it as a Light Forwarder, it will turn off the UI (which is fine for a deployment server).

You could also set outputs.conf directly and enable the Light Forwarder from the CLI.

ciandro84
Engager

Nice. So how do you do that? 🙂

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...