<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to edit serverclass.conf by CLI? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-edit-serverclass-conf-by-CLI/m-p/346320#M12890</link>
    <description>&lt;P&gt;Thank you for the reply.   I will look at the post and check the tool.&lt;/P&gt;

&lt;P&gt;But the part I am not clear on is writing the stanzas, so here is my attempt&lt;/P&gt;

&lt;P&gt;in /opt/splunk/etc/system/local&lt;BR /&gt;
edit serverclass.conf to create class and add clients&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#This server class is for my AWS instances
[serverClass:AWS_instances]
whitelist.0 = ip-192-168-1-* (for example all the instance names start with ip-192-168-1-[x].ec2.internal)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So now I need to create some inputs and outputs for the class (for example aws_inputs, aws_outputs)&lt;BR /&gt;
in /opt/splunk/etc/deployment-apps/&lt;/P&gt;

&lt;P&gt;this is where I get stuck...&lt;/P&gt;

&lt;P&gt;I see previously created deployment-apps (folders) in the directory, &lt;BR /&gt;
when I cd into them I see default and local, local has only app.conf with one comment #Autogenerated file&lt;BR /&gt;
but default has an outputs.conf with the correct information.&lt;/P&gt;

&lt;P&gt;The inputs will be monitoring a log source, which I could enter on each end point but would rather deploy an app.&lt;/P&gt;

&lt;P&gt;Please advise how I create the two apps by CLI?  Or possibly I am missing the CLI instructions.&lt;/P&gt;

&lt;P&gt;Do I create a couple more stanzas in serverclass.conf?  will that auto-create the deployment apps?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#This is for aws instances inputs
[serverClass:AWS_instances:app:aws_inputs]
stateOnClient = enabled
restartSplunkd = true

#This is for aws instances outputs
[serverClass:AWS_instances:app:aws_outputs]
stateOnClient = enabled
restartSplunkd = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 19:07:00 GMT</pubDate>
    <dc:creator>Log_wrangler</dc:creator>
    <dc:date>2020-09-29T19:07:00Z</dc:date>
    <item>
      <title>How to edit serverclass.conf by CLI?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-edit-serverclass-conf-by-CLI/m-p/346318#M12888</link>
      <description>&lt;P&gt;Normally I would use the deployment server GUI under setting &amp;gt; Distributed Environment &amp;gt; Forwarder management to create a server class, add clients, and then add apps (for inputs and outputs) to be deployed.  &lt;/P&gt;

&lt;P&gt;But for some reason the GUI is read only, I believe it is due to "flterType = blacklist " in many serverclass stanzas, but I am not sure how to edit the stanza so the GUI will work again.&lt;/P&gt;

&lt;P&gt;So going manual edit route via CLI,  I am not making sense of the syntax for directly editing the serverclass.conf.&lt;/P&gt;

&lt;P&gt;Could any one walk me thru how to edit the server class?&lt;/P&gt;

&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 16 Apr 2018 20:24:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-edit-serverclass-conf-by-CLI/m-p/346318#M12888</guid>
      <dc:creator>Log_wrangler</dc:creator>
      <dc:date>2018-04-16T20:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to edit serverclass.conf by CLI?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-edit-serverclass-conf-by-CLI/m-p/346319#M12889</link>
      <description>&lt;P&gt;A better, more controlled approach would be to edit serverclass.conf directly.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.2/Updating/Updateconfigurations#When_editing_serverclass.conf_directly"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.2/Updating/Updateconfigurations#When_editing_serverclass.conf_directly&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You can looks for which serverclass.conf is storing your serverclass configuration by using btool command on the deployment server:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;./splunk btool serverclass list --debug | grep "\["
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 16 Apr 2018 20:39:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-edit-serverclass-conf-by-CLI/m-p/346319#M12889</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-04-16T20:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to edit serverclass.conf by CLI?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-edit-serverclass-conf-by-CLI/m-p/346320#M12890</link>
      <description>&lt;P&gt;Thank you for the reply.   I will look at the post and check the tool.&lt;/P&gt;

&lt;P&gt;But the part I am not clear on is writing the stanzas, so here is my attempt&lt;/P&gt;

&lt;P&gt;in /opt/splunk/etc/system/local&lt;BR /&gt;
edit serverclass.conf to create class and add clients&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#This server class is for my AWS instances
[serverClass:AWS_instances]
whitelist.0 = ip-192-168-1-* (for example all the instance names start with ip-192-168-1-[x].ec2.internal)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So now I need to create some inputs and outputs for the class (for example aws_inputs, aws_outputs)&lt;BR /&gt;
in /opt/splunk/etc/deployment-apps/&lt;/P&gt;

&lt;P&gt;this is where I get stuck...&lt;/P&gt;

&lt;P&gt;I see previously created deployment-apps (folders) in the directory, &lt;BR /&gt;
when I cd into them I see default and local, local has only app.conf with one comment #Autogenerated file&lt;BR /&gt;
but default has an outputs.conf with the correct information.&lt;/P&gt;

&lt;P&gt;The inputs will be monitoring a log source, which I could enter on each end point but would rather deploy an app.&lt;/P&gt;

&lt;P&gt;Please advise how I create the two apps by CLI?  Or possibly I am missing the CLI instructions.&lt;/P&gt;

&lt;P&gt;Do I create a couple more stanzas in serverclass.conf?  will that auto-create the deployment apps?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#This is for aws instances inputs
[serverClass:AWS_instances:app:aws_inputs]
stateOnClient = enabled
restartSplunkd = true

#This is for aws instances outputs
[serverClass:AWS_instances:app:aws_outputs]
stateOnClient = enabled
restartSplunkd = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:07:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-edit-serverclass-conf-by-CLI/m-p/346320#M12890</guid>
      <dc:creator>Log_wrangler</dc:creator>
      <dc:date>2020-09-29T19:07:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to edit serverclass.conf by CLI?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-edit-serverclass-conf-by-CLI/m-p/346321#M12891</link>
      <description>&lt;P&gt;You create the app on /opt/splunk/etc/deployment-apps/YourAppName (which will include a default OR local directory with inputs.conf with your monitoring statements). I'll recommend you create a aws_props_transforms app which will have your sourcetype definitions (line breaking , timestamp parsing etc) as well. This app will go to your indexers Or heavy forwarders.  Now to assign your aws servers (deployment clients) those apps, you'll add the app assignment stanza within your AWS_instances serverclass, like this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; [serverClass:AWS_instances]
 whitelist.0 = ip-192-168-1-*
restartSplunkd = true
[serverClass:AWS_instances:app:aws_outputs]
[serverClass:AWS_instances:app:aws_outputs]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Other attributes (stateOnClient) are using default values, so I'm ignoring it. Reload or restart your deployment server instance for these changes to take effect (reload happens automatically when you make these changes by UI).&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:07:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-edit-serverclass-conf-by-CLI/m-p/346321#M12891</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2020-09-29T19:07:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to edit serverclass.conf by CLI?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-edit-serverclass-conf-by-CLI/m-p/346322#M12892</link>
      <description>&lt;P&gt;You can see this for what all stuff you add to your serverclass.conf&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.3/Updating/Useserverclass.conf"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.3/Updating/Useserverclass.conf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Apr 2018 21:46:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-edit-serverclass-conf-by-CLI/m-p/346322#M12892</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-04-16T21:46:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to edit serverclass.conf by CLI?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-edit-serverclass-conf-by-CLI/m-p/346323#M12893</link>
      <description>&lt;P&gt;Thank you very much for the outstanding explanation.&lt;BR /&gt;&lt;BR /&gt;
Please convert to an answer so I can accept.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2018 13:35:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-edit-serverclass-conf-by-CLI/m-p/346323#M12893</guid>
      <dc:creator>Log_wrangler</dc:creator>
      <dc:date>2018-04-17T13:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to edit serverclass.conf by CLI?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-edit-serverclass-conf-by-CLI/m-p/346324#M12894</link>
      <description>&lt;P&gt;Here you go.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2018 15:51:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-edit-serverclass-conf-by-CLI/m-p/346324#M12894</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-04-17T15:51:47Z</dc:date>
    </item>
  </channel>
</rss>

