Getting Data In

Running a Universal Forwarder on the same server as the Enterprise server.

acsplunkuser
Engager

I have a Solaris 10 standalone server. Can I run a Universal Forwarder (6.0.2) on the same server that Enterprise (also 6.0.2) is running on with the forwarder sending to Enterprise on this same server? This is for testing/learning/evaluation and not expected to be the final configuration. I looked through the 'Answers' area but came up blank. Thanks

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

I see no reason why not, there's a few pitfalls though: Make sure you're disciplined about paths and ports.
By default, full Splunk installs end up in /opt/splunk and UF installs end up in /opt/splunkforwarder, which can lead to tab completion mistakes if you're not careful.
Similarly, by default both will try to use port 8089 for their management port - that needs to be changed on at least one obviously. Here Splunk's quite helpful by asking you to change it on first launch if the default is in use already.

View solution in original post

0 Karma

markakirkland
Path Finder

I realize that this is a very late answer... but, I would like to add that, in addition to the above, if you are running Linux<=6.9 (just not sure about 7.x)... AND you "enable boot-start"... Splunk UF and Splunk Enterprise have the same name. In other words , I had to modify the name of the forwarder script in init.d and manually add the script to chkconfig.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

I see no reason why not, there's a few pitfalls though: Make sure you're disciplined about paths and ports.
By default, full Splunk installs end up in /opt/splunk and UF installs end up in /opt/splunkforwarder, which can lead to tab completion mistakes if you're not careful.
Similarly, by default both will try to use port 8089 for their management port - that needs to be changed on at least one obviously. Here Splunk's quite helpful by asking you to change it on first launch if the default is in use already.

0 Karma

acsplunkuser
Engager

Thanks for the help. And after spending time in the online documentation I came across this note in the section explaining the Universal Forwarder:
Note: The universal forwarder is a separate executable from full Splunk Enterprise. Instances of full Splunk Enterprise and the universal forwarder can co-exist on the same system.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...