Getting Data In

Universal Forwarder and Splunk Technology Add-on for Windows questions

aberdamy
Explorer

Does anyone know if there are any docs out there that describe the design/architecture of the Universal forwarder and Technology Add-on for Windows? Has anyone had any issues with these forwarders on domain controllers? Does the agent leave anything behind when it is uninstalled?

thanks in advance,

aberdamy

0 Karma

lukejadamec
Super Champion

Other than the documents for the App and the information this Answers site there are none, you should contact Splunk Support if you're having a specific problem.

I have had issues with these forwarders on Domain Controllers - check points on log files can get 'lost' causing 24+MB/minute of splunkd logs, which can slow down the system. Another problem is that when logging is enabled on the DCs, it can slow down the system.

The agent should uninstall via Windows Control Panel > Uninstall cleanly.

0 Karma

lukejadamec
Super Champion

When the forward would act up it would slow down the indexer, but that was when it was 32 bit. It does not seem to effect the 64 bit system.
The DC logs will slow down the DC, but if you already have logging enabled the forwarder should not cause a problem.

0 Karma

aberdamy
Explorer

Thanks for your reply. When you say "slow down the system" are you referring to the indexer or the domain controller after you installed the forwarder? Logging is already turned on for all of our dc's.

thanks

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...