All Apps and Add-ons

Can the Splunk for Asset Discovery app be installed on a Universal Forwarder?

msudhindra
Path Finder

Can the Splunk for Asset Discovery app be installed on a Universal Forwarder ?

I would like a Universal Forwarder system be the one that scans all the IP address ranges for availability, and then send the information to the indexers.

I can install nmap on my forwarder and that should not be an issue. Also, the app can be pushed out in its fully configured state using the Deployment Server, so the lack of a GUI on the forwarder should not hinder the deployment either.

Any help here would be greatly appreciated.

Thanks and Regards,
Madan

0 Karma
1 Solution

mw
Splunk Employee
Splunk Employee

Yes, it's designed to be used from a UF. As you said, you'll want to deploy nmap, and the app can be configured and deployed via DS as normal. The included scripted inputs can be configured to scan whatever IP range you'd like, but by default (i.e. with no target provided) they'll figure out what subnet(s) they're on and scan those. Due to that, you can easily deploy the app to each subnet and scan all in parallel, very quickly.

View solution in original post

mw
Splunk Employee
Splunk Employee

Yes, it's designed to be used from a UF. As you said, you'll want to deploy nmap, and the app can be configured and deployed via DS as normal. The included scripted inputs can be configured to scan whatever IP range you'd like, but by default (i.e. with no target provided) they'll figure out what subnet(s) they're on and scan those. Due to that, you can easily deploy the app to each subnet and scan all in parallel, very quickly.

msudhindra
Path Finder

Thanks a lot !

I'll get started on configuring this

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...