Getting Data In

Running a Universal Forwarder on the same server as the Enterprise server.

acsplunkuser
Engager

I have a Solaris 10 standalone server. Can I run a Universal Forwarder (6.0.2) on the same server that Enterprise (also 6.0.2) is running on with the forwarder sending to Enterprise on this same server? This is for testing/learning/evaluation and not expected to be the final configuration. I looked through the 'Answers' area but came up blank. Thanks

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

I see no reason why not, there's a few pitfalls though: Make sure you're disciplined about paths and ports.
By default, full Splunk installs end up in /opt/splunk and UF installs end up in /opt/splunkforwarder, which can lead to tab completion mistakes if you're not careful.
Similarly, by default both will try to use port 8089 for their management port - that needs to be changed on at least one obviously. Here Splunk's quite helpful by asking you to change it on first launch if the default is in use already.

View solution in original post

0 Karma

markakirkland
Path Finder

I realize that this is a very late answer... but, I would like to add that, in addition to the above, if you are running Linux<=6.9 (just not sure about 7.x)... AND you "enable boot-start"... Splunk UF and Splunk Enterprise have the same name. In other words , I had to modify the name of the forwarder script in init.d and manually add the script to chkconfig.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

I see no reason why not, there's a few pitfalls though: Make sure you're disciplined about paths and ports.
By default, full Splunk installs end up in /opt/splunk and UF installs end up in /opt/splunkforwarder, which can lead to tab completion mistakes if you're not careful.
Similarly, by default both will try to use port 8089 for their management port - that needs to be changed on at least one obviously. Here Splunk's quite helpful by asking you to change it on first launch if the default is in use already.

0 Karma

acsplunkuser
Engager

Thanks for the help. And after spending time in the online documentation I came across this note in the section explaining the Universal Forwarder:
Note: The universal forwarder is a separate executable from full Splunk Enterprise. Instances of full Splunk Enterprise and the universal forwarder can co-exist on the same system.

0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials

Welcome to the "Splunk Classroom Chronicles" series, created to help curious, career-minded learners get ...

Access Tokens Page - New & Improved

Splunk Observability Cloud recently launched an improved design for the access tokens page for better ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

&#x1f342; Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...