Getting Data In

How to add a forwarder manager server to a dev-testing stand-alone instance of splunk?

packet_hunter
Contributor

I have a stand-alone Dev instance of splunk running on Linux.

It works great for testing.

But now I have to do some testing with Universal Forwarders and need a forwarder manager.

Any advise to add this to the mix?

Can a forwarder manager role be added to the stand-alone or do I need to run another instance as just a forwarder manager?

Thank you

Tags (2)
0 Karma
1 Solution

adonio
Ultra Champion

Hello packet_hunter,
Yes you can!
enable your single instance as a deployment server (forwarder management instance) by telling the forwarders to be deployment clients of that instance
read more here:
https://docs.splunk.com/Documentation/Splunk/6.6.0/Updating/Deploymentserverarchitecture
hope it helps

View solution in original post

0 Karma

adonio
Ultra Champion

Hello packet_hunter,
Yes you can!
enable your single instance as a deployment server (forwarder management instance) by telling the forwarders to be deployment clients of that instance
read more here:
https://docs.splunk.com/Documentation/Splunk/6.6.0/Updating/Deploymentserverarchitecture
hope it helps

0 Karma

packet_hunter
Contributor

how / where do you enable the instance to be a deployment server ?

0 Karma

adonio
Ultra Champion

once a forwarder or other splunk instance is phoning to it using the deploymentclient.conf configuration, your instance will "become" a deployment server.
then you can navigate to settings -> forawrder management and see the client who phoned home.
now you can place apps in /etc/deployment-app folder and see them on the same page
create serverclseess to map apps to clients and the DS will push the apps to forwarders

0 Karma

packet_hunter
Contributor

so I should have mentioned that I manually installed a UF on a test windows box already, but nothing is coming into the standalone...

I think I follow what you are saying... so I will recheck my work.

Thank you

0 Karma

adonio
Ultra Champion

place a deploymentclient.conf in your forwarder /etc/system/local directory
restart the forwarder, or use the cli:
https://docs.splunk.com/Documentation/Splunk/6.6.0/Updating/Configuredeploymentclients

0 Karma

packet_hunter
Contributor

ok I am tracking now, thank you.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...