Splunk Enterprise Security

Splunk Cloud Hybrid Infrastructure

kruane
Explorer

So I have Splunk Cloud, but we still use a Heavy Forwarder, Universal Forwarder and a Deployment server. The UF server has definitely come into hand for grabbing local data. However, I'm not sure what the Deployment server is for. We do use the Heavy Forwarder for various things. 

Does anyone have documentation of what is necessary and what is a nicety? And do they have knowledge on the specs needed? 

Labels (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Strictly speaking, none of it is necessary, but it does make it easier to get data into Splunk.  😃

You already use the UF and HF so you must have found them necessary for doing certain things.  There may be other ways to do those things, but don't fix what isn't broken.

The Deployment Server is there to help manage your UFs.  Without a DS, you have manage each UF separately and manually (unless you have automation to help).

For more about the DS and what is does, see https://docs.splunk.com/Documentation/Splunk/9.2.1/Updating/Aboutdeploymentserver#What_is_deployment... .  The system requirements are at https://docs.splunk.com/Documentation/Splunk/9.2.1/Updating/Planadeployment#Deployment_server_system...

System requirements for UFs are at https://docs.splunk.com/Documentation/Forwarder/9.2.1/Forwarder/Deploy

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...