Getting Data In

Running a Universal Forwarder on the same server as the Enterprise server.

acsplunkuser
Engager

I have a Solaris 10 standalone server. Can I run a Universal Forwarder (6.0.2) on the same server that Enterprise (also 6.0.2) is running on with the forwarder sending to Enterprise on this same server? This is for testing/learning/evaluation and not expected to be the final configuration. I looked through the 'Answers' area but came up blank. Thanks

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

I see no reason why not, there's a few pitfalls though: Make sure you're disciplined about paths and ports.
By default, full Splunk installs end up in /opt/splunk and UF installs end up in /opt/splunkforwarder, which can lead to tab completion mistakes if you're not careful.
Similarly, by default both will try to use port 8089 for their management port - that needs to be changed on at least one obviously. Here Splunk's quite helpful by asking you to change it on first launch if the default is in use already.

View solution in original post

0 Karma

markakirkland
Path Finder

I realize that this is a very late answer... but, I would like to add that, in addition to the above, if you are running Linux<=6.9 (just not sure about 7.x)... AND you "enable boot-start"... Splunk UF and Splunk Enterprise have the same name. In other words , I had to modify the name of the forwarder script in init.d and manually add the script to chkconfig.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

I see no reason why not, there's a few pitfalls though: Make sure you're disciplined about paths and ports.
By default, full Splunk installs end up in /opt/splunk and UF installs end up in /opt/splunkforwarder, which can lead to tab completion mistakes if you're not careful.
Similarly, by default both will try to use port 8089 for their management port - that needs to be changed on at least one obviously. Here Splunk's quite helpful by asking you to change it on first launch if the default is in use already.

0 Karma

acsplunkuser
Engager

Thanks for the help. And after spending time in the online documentation I came across this note in the section explaining the Universal Forwarder:
Note: The universal forwarder is a separate executable from full Splunk Enterprise. Instances of full Splunk Enterprise and the universal forwarder can co-exist on the same system.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...