Getting Data In

Deployment server and Universal Forwarder

ciandro84
Engager

Does the deployment server come with a universal forwarder of its own already installed on it?
I have a central indexer and on another server I have the deployment server setup.

Is there a universal forwarder installed on the deployment server so that it can log data about that server to my central indexer?

Thanks!

0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Actually Deployment Server is just a variant configuration of the standard Splunk Enterprise installation. You can configure it to operate as both a Deployment Server and a Splunk Light Forwarder. A Light Forwarder functions and is configured substantially identically to a Universal Forwarder, though the setup and installation is slightly different.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

Actually Deployment Server is just a variant configuration of the standard Splunk Enterprise installation. You can configure it to operate as both a Deployment Server and a Splunk Light Forwarder. A Light Forwarder functions and is configured substantially identically to a Universal Forwarder, though the setup and installation is slightly different.

lguinn2
Legend

Just install Splunk on the box that will be the deployment server. Then go into the Manager and look for Forwarding and Receiving. Set the forwarding options. BTW, if you set it as a Light Forwarder, it will turn off the UI (which is fine for a deployment server).

You could also set outputs.conf directly and enable the Light Forwarder from the CLI.

ciandro84
Engager

Nice. So how do you do that? 🙂

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...