Getting Data In

How do I make my heavy forwarder, which is already configured, into a deployment server?

kdelvillar
Engager

I have a Splunk Cloud instance and a heavy forwarder that sends in all my data into my cloud instance. I will now be installing a universal forwarder to get Windows Active Directory data in and will point my universal forwarder to my heavy forwarder. Now, my question is how do I make my heavy forwarder that is already configured into a deployment server as well? I would also like to know how do I know if my heavy forwarder is already set up as a deployment server? (I didn't set up the HF someone else did)

Thanks

0 Karma

vincenteous
Communicator

Hi,

Technically you can install your UF and then point the deployment server to your currently existing HF. And then, you can check your UF's availability using your HF's Web GUI in "Settings --> Forwarder Management" menu. Once you can see your UF, you can then create a server class and push app to that UF.

Make sure to have a firewall rule (if there's firewall in between) to allow communication between your UF and HF on port 8089 or any other management port you use. To confirm the connection from your UF side, see splunkd.log and find entry which contains "Handshake".

Hope it helps.

0 Karma

dkeck
Influencer

Please accept the answer if it was helpful

0 Karma

dkeck
Influencer

Its is recommended to install your DS on a dedicated server, not on a HF.

So if you expect to have a high number of Clients (100+) choose a dedicated server , or at least a SH or your License Master

You can check on each splunk instance if its a deployment server by simple clicking on the settings -> forwarder management tab
or check $SPLUNK_HOME/etc/deployment-apps, any apps in there, its at least ready to be a DS.

This is also the way to "actived" the DS function just add apps to $SPLUNK_HOME/etc/deployment-apps

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...