Getting Data In

How to add a forwarder manager server to a dev-testing stand-alone instance of splunk?

packet_hunter
Contributor

I have a stand-alone Dev instance of splunk running on Linux.

It works great for testing.

But now I have to do some testing with Universal Forwarders and need a forwarder manager.

Any advise to add this to the mix?

Can a forwarder manager role be added to the stand-alone or do I need to run another instance as just a forwarder manager?

Thank you

Tags (2)
0 Karma
1 Solution

adonio
Ultra Champion

Hello packet_hunter,
Yes you can!
enable your single instance as a deployment server (forwarder management instance) by telling the forwarders to be deployment clients of that instance
read more here:
https://docs.splunk.com/Documentation/Splunk/6.6.0/Updating/Deploymentserverarchitecture
hope it helps

View solution in original post

0 Karma

adonio
Ultra Champion

Hello packet_hunter,
Yes you can!
enable your single instance as a deployment server (forwarder management instance) by telling the forwarders to be deployment clients of that instance
read more here:
https://docs.splunk.com/Documentation/Splunk/6.6.0/Updating/Deploymentserverarchitecture
hope it helps

0 Karma

packet_hunter
Contributor

how / where do you enable the instance to be a deployment server ?

0 Karma

adonio
Ultra Champion

once a forwarder or other splunk instance is phoning to it using the deploymentclient.conf configuration, your instance will "become" a deployment server.
then you can navigate to settings -> forawrder management and see the client who phoned home.
now you can place apps in /etc/deployment-app folder and see them on the same page
create serverclseess to map apps to clients and the DS will push the apps to forwarders

0 Karma

packet_hunter
Contributor

so I should have mentioned that I manually installed a UF on a test windows box already, but nothing is coming into the standalone...

I think I follow what you are saying... so I will recheck my work.

Thank you

0 Karma

adonio
Ultra Champion

place a deploymentclient.conf in your forwarder /etc/system/local directory
restart the forwarder, or use the cli:
https://docs.splunk.com/Documentation/Splunk/6.6.0/Updating/Configuredeploymentclients

0 Karma

packet_hunter
Contributor

ok I am tracking now, thank you.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...