Getting Data In

How to manage Splunk forwarders from a Splunk deployment server installed on a different VM?

Suyalag
New Member

So, I have Splunk Enterprise installed on a VM and it runs fine, but so far I have been upgrading the Splunk forwarders manually. I want to install Splunk on a different VM and manage the forwarders from there. How do I connect this new install of a Splunk deployment server to the one that runs the searches and has all the data? I am new to Splunk, so any help is appreciated.

Thanks!

0 Karma

ddrillic
Ultra Champion

One thing to keep in mind that with the new versions of Splunk, you can manage the forwarders from the Distributed Management Console.

For example, you can see a breakdown of the forwarders by version -

forwarders by version

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

This part of our documentation should get you started in understanding how the deployment server works.

Any Splunk instance (other then the deployment server itself) that you want to manage is configured to connect to the deployment server via the deploymentclient.conf configuration file.
Deployment clients will periodically connect to the DS to check wether any updated configuration is available, download those updates and apply them locally.
The deployment server will use the configuration file serverclass.conf to map deployment applications to groups of clients based on rules you define.

As long as you can connect from deployment clients to the DS via port 8089, the setup is pretty straightforward.
Please review the documentation linked above and let us know if you have issues.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...