Getting Data In

Where should I put my syslog universal forwarder/deployment server with regards to subnets and firewalls in an indexer clustering environment?

hettervik
Builder

Hi folks,

I'm planning on installing some new machines running Splunk instances. Two of the machines are going to run an indexer cluster, one a cluster master and one a search head. The last machine is going to run both a deployment server and a syslog universal forwarder, where syslogs are going to be written to file on the forwarder and forwarded to the indexer cluster. The deployment server is going to deploy apps to the forwarders and (probably) to the one search head.

What I'm wondering is where it would be most logical to put my syslog forwarder/deployment server? Does it make sense to put it in the same subnet as the indexer cluster, cluster master, and search head to keep it nice and simple, or would this possibly make it difficult for apps/configuration to be deployed to forwarders outside the subnet? The alternative would be to make it "external", outside the subnet of the indexer cluster, cluster master, and search head. I'm sorry that I can't give you any details regarding firewalls, domains, etc., mainly because I don't know myself due to the complexity of the system I'm dealing with. I was just hoping someone had any experience with similar cases?

Any input would be much appreciated, thanks!

0 Karma
1 Solution

dgrubb_splunk
Splunk Employee
Splunk Employee

As long as your deployment clients have connectivity to your deployment server's mangement port. I do not see any additional benefit by placing the deployment client in the same subnet as your indexer cluster.

View solution in original post

0 Karma

dgrubb_splunk
Splunk Employee
Splunk Employee

As long as your deployment clients have connectivity to your deployment server's mangement port. I do not see any additional benefit by placing the deployment client in the same subnet as your indexer cluster.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...