Getting Data In

Deployment server and Universal Forwarder

ciandro84
Engager

Does the deployment server come with a universal forwarder of its own already installed on it?
I have a central indexer and on another server I have the deployment server setup.

Is there a universal forwarder installed on the deployment server so that it can log data about that server to my central indexer?

Thanks!

0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Actually Deployment Server is just a variant configuration of the standard Splunk Enterprise installation. You can configure it to operate as both a Deployment Server and a Splunk Light Forwarder. A Light Forwarder functions and is configured substantially identically to a Universal Forwarder, though the setup and installation is slightly different.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

Actually Deployment Server is just a variant configuration of the standard Splunk Enterprise installation. You can configure it to operate as both a Deployment Server and a Splunk Light Forwarder. A Light Forwarder functions and is configured substantially identically to a Universal Forwarder, though the setup and installation is slightly different.

lguinn2
Legend

Just install Splunk on the box that will be the deployment server. Then go into the Manager and look for Forwarding and Receiving. Set the forwarding options. BTW, if you set it as a Light Forwarder, it will turn off the UI (which is fine for a deployment server).

You could also set outputs.conf directly and enable the Light Forwarder from the CLI.

ciandro84
Engager

Nice. So how do you do that? 🙂

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...