Getting Data In

Can a universal forwarder work without connectivity to a deployment server?

eastlandm
New Member

We have universal forwarders planned for the DMZ. Firewall admins want to limit connectivity to as few ports as possible.

I know the UF needs to connect to the indexer (TCP-9997), but can it live without communicating to the deployment server (TCP-8089)?

No apps are required, and I plan on just configuring inputs.conf directly as only logfile & perfmon counters are required.

So questions needing answers:
1. Will the UF start up and operate if it can't communicate with the deployment server?
2. Is there any configuration required to be done to allow UF to operate without access to a deployment server?

I've looked at an intermediate forwarder, but f/w admins don't like dmz hosts talking to each other, so that option is out.

0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

You UF / HF can work without a deployment server. In your case, since these are in a DMZ without connectivity to the deployment server (DS), you should just configure these without a DS. Then configure your inputs manually and distribute them to these hosts.

Even if they did connect to a DS, and then loose connectivity, they will still function. The only issues arise when they reconnect to the DS, if apps are not the same, the client will redeploy and download all apps again.

So;
1) Yes
2) No

View solution in original post

esix_splunk
Splunk Employee
Splunk Employee

You UF / HF can work without a deployment server. In your case, since these are in a DMZ without connectivity to the deployment server (DS), you should just configure these without a DS. Then configure your inputs manually and distribute them to these hosts.

Even if they did connect to a DS, and then loose connectivity, they will still function. The only issues arise when they reconnect to the DS, if apps are not the same, the client will redeploy and download all apps again.

So;
1) Yes
2) No

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...