Deployment Architecture

How do you add additional deployed forwarders to existing server classes?

systemsadminist
Explorer

I have a server class called DomainControllers, and have 2 existing DCs that were added when I initially created the server class. I would like to simply add additional DCs to that server class, and I can't seem to find a quick way of doing so.

You would think it would be the same process as adding/removing when creating the server class in the beginning..

But no..

Tags (1)
0 Karma
1 Solution

adonio
Ultra Champion

why isnt it?
add deploymentclient.conf to your new DC forwarder, make sure ou can see it in forwarder management page in splunk DS gui, pick the correct serverclass, click edit, add clients, add the new forwarder, save, thats it

View solution in original post

0 Karma

adonio
Ultra Champion

why isnt it?
add deploymentclient.conf to your new DC forwarder, make sure ou can see it in forwarder management page in splunk DS gui, pick the correct serverclass, click edit, add clients, add the new forwarder, save, thats it

0 Karma

systemsadminist
Explorer

This is all in Splunk Cloud currently. So it is slightly different. However, you knocked a screw around and I was able to find the equivalent in the Cloud side of the mix.

Thanks for the help.

0 Karma

adonio
Ultra Champion

can you share in an answer what you have done and mark your question as answered?
also up vote any comment that helped.
happy its been resolved

0 Karma

systemsadminist
Explorer

No problem. I awarded you the points above since it is the correct way for Splunk On-Prem / Enterprise. As far as Splunk Cloud goes, an admin would need to go to:

Settings -> Forwarder Management -> Choose Server Classes -> Edit -> Edit Clients

A new window refreshes showing all existing clients/forwarders, and a Include (whitelist) field at the very top. Simply add in the name of the additional forward from the list and hit Save.

Thanks again

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...