Deployment Architecture

Push apps from deployment server automatically to universal forwarders when they connect

vikram_m
Path Finder

I have an app created and deployment client created.

I need to push the app automatically to the UFs which are connected. How can that be achieved?

For now UFs are connected to deployment server from there I add them in server class and push app. I want outputs.conf app should be automatically pushed to them.

Please help.

Thanks.
Vikram.

0 Karma

amahoski
Explorer

If you want to push outputs.conf itself see below:

you can use this link to be aware of .conf file precedence to accomplish this:

http://docs.splunk.com/Documentation/Splunk/6.6.3/Admin/Wheretofindtheconfigurationfiles

Create an app with an outputs.conf and push it out to the forwarder. The deployment server should find that the app has been created and automatically push it as long as the server has been added as a client machine to the server class itself.

Note that the system/local directory takes priority so you must ensure that the properties in system/local are not already utilized otherwise, it won't take precedence.

0 Karma

vikram_m
Path Finder

This was helpful amahoski but what I would like to know is, as I want to push outputs.conf automatically to the UFs, how can I achieve this functionality.

0 Karma

amahoski
Explorer

Can you provide more clarity on this? Forwarder management is just one methodology for managing forwarders. Adding apps to the server class is the "out of the box" method provided by splunk to add apps to remote universal forwarders.

Do you want to push the outputs.conf file itself to the forwarder?

If so, you can use this link to accomplish this:

http://docs.splunk.com/Documentation/Splunk/6.6.3/Admin/Wheretofindtheconfigurationfiles

Create an app with an outputs.conf and push it out to the forwarder. Note that the system/local directory takes priority so you must ensure that the properties in system/local are not already utilized otherwise, it won't take precedence.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...