Getting Data In

deployment-server question

fisk12
Path Finder

in this manual http://www.splunk.com/base/Documentation/latest/Deploy/Extendedexampledeployseveralstandardforwarder...

they say that i should run this command as part of configuration.

./splunk enable listen 9997 -auth :

when i do it on the machine that is supposed to work as a deployment server i get this error

./splunk enable listen 9997 -auth :

Command error: The subcommand 'listen' is not valid for command 'enable'.

Steve_G_
Splunk Employee
Splunk Employee

Forwarders send data to receivers, which are usually indexers. The "enable listen" command is the command that you run on the receiver, not the forwarder. It allows the receiver to listen for data coming from a forwarder.

How you set up a deployment server to communicate with deployment clients is a separate issue, which is convered in the earlier steps in that example.

For more information on forwarding and receiving, refer to:

http://www.splunk.com/base/Documentation/latest/Deploy/Aboutforwardingandreceivingdata

fisk12
Path Finder

Splunk Universal Forwarder 4.2.1 (build 98164)

Am i supposed to run the command on the deployer-server or the client?

0 Karma

jkerai
Splunk Employee
Splunk Employee

It should be run on the indexer that will listen and receive data from from universal forwarder on port 9997. I am assuming that your indexer will serve the purpose of Deployment Server as well. If so, you can run the command on DeploymentServer/indexer.

0 Karma

jkerai
Splunk Employee
Splunk Employee

Could you provide the output of following command 'splunk version'. Can you check if you are running the command on indexer or Universal forwarder?

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how ...