All Apps and Add-ons

Can the Splunk for Asset Discovery app be installed on a Universal Forwarder?

msudhindra
Path Finder

Can the Splunk for Asset Discovery app be installed on a Universal Forwarder ?

I would like a Universal Forwarder system be the one that scans all the IP address ranges for availability, and then send the information to the indexers.

I can install nmap on my forwarder and that should not be an issue. Also, the app can be pushed out in its fully configured state using the Deployment Server, so the lack of a GUI on the forwarder should not hinder the deployment either.

Any help here would be greatly appreciated.

Thanks and Regards,
Madan

0 Karma
1 Solution

mw
Splunk Employee
Splunk Employee

Yes, it's designed to be used from a UF. As you said, you'll want to deploy nmap, and the app can be configured and deployed via DS as normal. The included scripted inputs can be configured to scan whatever IP range you'd like, but by default (i.e. with no target provided) they'll figure out what subnet(s) they're on and scan those. Due to that, you can easily deploy the app to each subnet and scan all in parallel, very quickly.

View solution in original post

mw
Splunk Employee
Splunk Employee

Yes, it's designed to be used from a UF. As you said, you'll want to deploy nmap, and the app can be configured and deployed via DS as normal. The included scripted inputs can be configured to scan whatever IP range you'd like, but by default (i.e. with no target provided) they'll figure out what subnet(s) they're on and scan those. Due to that, you can easily deploy the app to each subnet and scan all in parallel, very quickly.

msudhindra
Path Finder

Thanks a lot !

I'll get started on configuring this

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...