Splunk Enterprise

Need help with Deployment Server – Clients not showing up

BraxcBT
Explorer

Hi team,

I need some help with setting up the Splunk Deployment Server.

I’ve configured the deploymentclient.conf file on a Universal Forwarder and set up a server class via the Splunk UI on my Heavy Forwarder, which I'm using as the Deployment Server. However, I’m not seeing the client listed under the server class or in the deployment server's list of connected clients.

Is there anything I might be missing in the setup or configuration?
Any advice would be appreciated!

Thanks in advance!

Labels (1)
0 Karma
1 Solution

PrewinThomas
Motivator

@BraxcBT 

Which version of Splunk are you running?
If you are on Splunk Enterprise 9.2 or later, make sure you have the following configuration to ensure Universal Forwarders show up in the Forwarder Management UI.

add these settings to outputs.conf

[indexAndForward]
index = true
selectiveIndexing = true


#https://help.splunk.com/en/splunk-enterprise/administer/update-your-deployment/9.2/configure-the-dep...


Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

View solution in original post

PrewinThomas
Motivator

@BraxcBT 

Which version of Splunk are you running?
If you are on Splunk Enterprise 9.2 or later, make sure you have the following configuration to ensure Universal Forwarders show up in the Forwarder Management UI.

add these settings to outputs.conf

[indexAndForward]
index = true
selectiveIndexing = true


#https://help.splunk.com/en/splunk-enterprise/administer/update-your-deployment/9.2/configure-the-dep...


Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

BraxcBT
Explorer

Thx, it works

0 Karma

isoutamo
SplunkTrust
SplunkTrust
FYI: With 9.4 or something there is nasty feature which shows only GUIDs etc. in default field. Fortunately there is setting link/button on headers from where you can select "missing" fields. Unfortunately this is not a permanent settings, so you must do it again and again 😞
0 Karma

squinlan2
Explorer

Would you be able to share a sanitized version of your deploymentclient.conf?

0 Karma

BraxcBT
Explorer

Hi, @squinlan2 

Sure, 

deploymentclient.conf
[deployment-client]
clientName = UF-LAB

[target-broker:deploymentServer]
targetUri = 192.168.*.*:8089

serverclass.conf

[serverClass:windowsAD:app:sendtoindexer]
restartSplunkd = true
stateOnClient = enabled

[serverClass:windowsAD]
whitelist.0 = UF-LAB

I've been doing some tests. I created an app under deployment-apps and then a server class where the client name is UF-LAB. I reloaded the deployment server and the app worked — I can see the server class and the app. However, I don't see the forwarder listed in the UI. Also, when I run the command splunk list deploy-clients, it says:
"No deployment clients have contacted this server."

Can you help me improve this?

BraxcBT_0-1759451859950.png

BraxcBT_2-1759451920011.png

 

BraxcBT_1-1759451882697.png

 

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...