i have 3 indexes and 3 Search heads.
i also have a cluster master server.
i'm trying to connect my universal-forwarder in order to send logs from remote servers to the indexers (through the cluster master)
how can i to configure the connection between the UF and the clusterMaster?
Thanks u for helping!
I believe you are looking for Indexer discovery option.
please find below link useful.
I believe there are two answers to this question....
the old way - have the forwarder send to multiple indexers
the Indexers Discovery Method - Indexer discovery is available only for forwarding to indexer clusters. Each forwarder queries the master node for a list of all peer nodes in the cluster. It then uses load balancing to forward data to the set of peer nodes.
as @soutamo said, it isn't possible to install or update a Universal forwarder from a Splunk server, but it's possible to push configurations to UFs.
To do this, you have to configure in your UFs a file (called deploymentclient.conf) where's the address of the Deployment Server, a Splunk server with the role to check and push configurations to UFs.
Deployment server must be a dedicated server if it has to manage more than 50 UFs, otherwise it can share this role with another one, but not Master Node, Indexer or Search Head.
So, you don't see any UF in your Master Node because you didin't configured deploymentclient.conf in UFs.
At the end: the correct approach to manage UFs is the following:
In this way, you'll be able to see in [Settings -- Forwarder Management] all the UFs and at this point you'll be able to create the ServerClasses to deploy configurations to UFs.
You can find a guide to the above steps at https://docs.splunk.com/Documentation/Splunk/8.0.5/Updating/Aboutdeploymentserver (read carefully these pages before to start!).
You must first install forwarders and define that those are sending logs to the indexer cluster. Then if you want to use deployment server you could star to define needed apps / input etc there.
Splunk haven’t any capability to install or upgrade UF, it just delivers configurations to the installed UF if/when they are registered to Deployment server.