One more comment about the configuration to connect your indexers or DS. Depending on how you install your configurations on those systems you must have almost always some configuration package to install with first time binary installation. In minimum this is package (splunk app) that contains information and needed certs to connect to Your Splunk Indexers. This apply if you are installing your collection apps via GPO, Ansible, manually or some other configuration tool. If you are using DS (deployment server) to deliver app configuration then you must install also DS client package into those UFs. Then just us DS as normally is used to deliver other packages. In that way you can see immediately, after UFs has installed and configured to configure your system, internal logs from those new UF. If/when you have configure some alerts for unknown logs then you can react and continue with onboarding process as planned.
... View more