Getting Data In

Running a Universal Forwarder on the same server as the Enterprise server.

acsplunkuser
Engager

I have a Solaris 10 standalone server. Can I run a Universal Forwarder (6.0.2) on the same server that Enterprise (also 6.0.2) is running on with the forwarder sending to Enterprise on this same server? This is for testing/learning/evaluation and not expected to be the final configuration. I looked through the 'Answers' area but came up blank. Thanks

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

I see no reason why not, there's a few pitfalls though: Make sure you're disciplined about paths and ports.
By default, full Splunk installs end up in /opt/splunk and UF installs end up in /opt/splunkforwarder, which can lead to tab completion mistakes if you're not careful.
Similarly, by default both will try to use port 8089 for their management port - that needs to be changed on at least one obviously. Here Splunk's quite helpful by asking you to change it on first launch if the default is in use already.

View solution in original post

0 Karma

markakirkland
Path Finder

I realize that this is a very late answer... but, I would like to add that, in addition to the above, if you are running Linux<=6.9 (just not sure about 7.x)... AND you "enable boot-start"... Splunk UF and Splunk Enterprise have the same name. In other words , I had to modify the name of the forwarder script in init.d and manually add the script to chkconfig.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

I see no reason why not, there's a few pitfalls though: Make sure you're disciplined about paths and ports.
By default, full Splunk installs end up in /opt/splunk and UF installs end up in /opt/splunkforwarder, which can lead to tab completion mistakes if you're not careful.
Similarly, by default both will try to use port 8089 for their management port - that needs to be changed on at least one obviously. Here Splunk's quite helpful by asking you to change it on first launch if the default is in use already.

0 Karma

acsplunkuser
Engager

Thanks for the help. And after spending time in the online documentation I came across this note in the section explaining the Universal Forwarder:
Note: The universal forwarder is a separate executable from full Splunk Enterprise. Instances of full Splunk Enterprise and the universal forwarder can co-exist on the same system.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...