Getting Data In

What's the significance of "add forward-server" on the universal forwarders?

awurster
Contributor

what's the significance of the add forward-server statement?

splunk add forward-server <host>:<port> -auth <username>:<password>

i'm documenting the forwarder install for some admins to read, and we previously had this step in there for a standalone deployment. i think we'll remove it though with our new distributed deployment.

according to the Answers and Docs it's optional, and i believe i'm hardcoding all the indexer addresses anyways in a forwarder package so it's not needed. it's just difficult for me to follow some of the docs because terminologies are used interchangeably and it sometimes becomes unclear.

0 Karma

josh_beverly
Explorer

I know this is a super old thread but I was wondering if you could clarify:

i believe i'm hardcoding all the indexer addresses anyways in a forwarder package so it's not needed.

Do you have some documentation on this process?

Any help is appreciated.

Thanks

0 Karma

sudosplunk
Motivator

The CLI command in question is used to configure receiving endpoint on Universal Forwarder. More info is available here. I am not sure if this is what you're looking for, but this definitely is a good starting point.

0 Karma

josh_beverly
Explorer

thankyou for the reply but i am specifically asking about hardcoding the indexer addresses in a forwarder package

0 Karma

sudosplunk
Motivator

In that case, you have to include outputs.conf with below settings, in your forwarder package.

## Syntax
[tcpout-server://<ip address>:<port>]

## Example
[tcpout-server://1.1.1.1:9997]

OR

##Syntax:
[tcpout:<target_group>]
server = [<ip>|<servername>]:<port>

##Example:
[tcpout:prod_indexer_group]
server = https://yourIndexer1:9997, https://yourIndexer2:9997

Please have a look at my other answer for more details on above settings. HTH!

0 Karma

chanfoli
Builder

The purpose of this CLI command is to add an indexer (or heavy forwarder) to outputs.conf - in a basic setup this is the CLI way to tell your forwarder where to forward to.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...