Getting Data In

What's the significance of "add forward-server" on the universal forwarders?

awurster
Contributor

what's the significance of the add forward-server statement?

splunk add forward-server <host>:<port> -auth <username>:<password>

i'm documenting the forwarder install for some admins to read, and we previously had this step in there for a standalone deployment. i think we'll remove it though with our new distributed deployment.

according to the Answers and Docs it's optional, and i believe i'm hardcoding all the indexer addresses anyways in a forwarder package so it's not needed. it's just difficult for me to follow some of the docs because terminologies are used interchangeably and it sometimes becomes unclear.

0 Karma

josh_beverly
Explorer

I know this is a super old thread but I was wondering if you could clarify:

i believe i'm hardcoding all the indexer addresses anyways in a forwarder package so it's not needed.

Do you have some documentation on this process?

Any help is appreciated.

Thanks

0 Karma

sudosplunk
Motivator

The CLI command in question is used to configure receiving endpoint on Universal Forwarder. More info is available here. I am not sure if this is what you're looking for, but this definitely is a good starting point.

0 Karma

josh_beverly
Explorer

thankyou for the reply but i am specifically asking about hardcoding the indexer addresses in a forwarder package

0 Karma

sudosplunk
Motivator

In that case, you have to include outputs.conf with below settings, in your forwarder package.

## Syntax
[tcpout-server://<ip address>:<port>]

## Example
[tcpout-server://1.1.1.1:9997]

OR

##Syntax:
[tcpout:<target_group>]
server = [<ip>|<servername>]:<port>

##Example:
[tcpout:prod_indexer_group]
server = https://yourIndexer1:9997, https://yourIndexer2:9997

Please have a look at my other answer for more details on above settings. HTH!

0 Karma

chanfoli
Builder

The purpose of this CLI command is to add an indexer (or heavy forwarder) to outputs.conf - in a basic setup this is the CLI way to tell your forwarder where to forward to.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...