Getting Data In

Heavy Forwarder as Deployment Server

Torben_Volkmann
New Member

Hello,

Is it possible to use a heavy forwarder as deployment server, too? I try to install 2 servers like this: http://answers.splunk.com/answers/37649/multiple-deployment-servers-configuration

Because the indexer is in a different subnet than some of the servers.

Thank you for your help.

Best regards,

Torben

0 Karma
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

It is possible to use a heavy forwarder as a deployment server, since it is a full instance of Splunk. Do you already have a Deployment Server? if this is a new one, it will work just fine out of the box. If you have to do a tiered option, there are some other considerations you will need.

View solution in original post

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

It is possible to use a heavy forwarder as a deployment server, since it is a full instance of Splunk. Do you already have a Deployment Server? if this is a new one, it will work just fine out of the box. If you have to do a tiered option, there are some other considerations you will need.

0 Karma

Torben_Volkmann
New Member

The whole environment is build from scratch. There is already a deployment server, but this is not able to reach server on side b. He is only able to reach the heavy forwarder and vice versa.

I think a tiered option is not necessary.

My question was created, because I received an error message in the forwared management on the heavy forwarder yesterday, which disapeared after I switched the licenses.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...