Reporting

connectivity between forwarder and deployment server

anoopambli
Communicator

Is there any CLI option in unversal forwarder to check if it is establishing connection with deployment server?

We are using HPOO automation tool to install splunk forwarder on windows and linux servers, last step of installation copies deploymentclient.conf file to %SPLUNK_HOME%\etc\system\local directory. Wanted to know if there is any command available to make sure that it can connect to deployment server.

Tags (1)
0 Karma

Drainy
Champion

There are a whole host of commands available which you can use on the UF or deployment server, have a look at;
http://docs.splunk.com/Documentation/Splunk/latest/Admin/CLIadmincommands

You can also have a look through splunkd.log to see for connections or app downloads.

DaveSavage
Builder

You may consider looking at the other end, albeit this doesn't strictly address your request - but to check the visibility of the host at the indexer confirms the forwarder is working AND gives you opportunity to check the data stream plus the rate of indexing. All that completes the job, as opposed to checking at the send end ?
If you have network access you would also see the traffic - worthwhile in case sure, it's sending but with no result i.e. you have firewall issues.

Drainy
Champion

My only comment on this is that it is the UF that initiates the connection when it phones home so in this case it is sometimes easier to quickly check on the UF that it is trying to connect

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...