Getting Data In

Universal Forwarder Deployment

New Member

Good morning,

i'm new to Splunk and have a question regarding universal forwarder deployment. I installed the UF on a windows machine, in order to configure it via the deploment server do i have to copy the SplunkForwarder folder from /opt/splunk/etc/apps to /opt/splunk/etc$ cd deployment-apps/ ?
And what files I have to configured to make the client send data to my indexer?

thanks in advanced

0 Karma

Splunk Employee
Splunk Employee

There is a highly detailed example using the Deployment Server and what configurations to deploy here.