<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What takes precedence, index.conf on Universal Forwarder, or Forwarder Management in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/What-takes-precedence-index-conf-on-Universal-Forwarder-or/m-p/432899#M15327</link>
    <description>&lt;P&gt;The apps received from the deployment server will be found on the forwarders in the $SPLUNK_HOME/etc/apps directory.  Deployment servers cannot touch $SPLUNK_HOME/etc/system.&lt;/P&gt;

&lt;P&gt;To answer the question in subject line, $SPLUNK_HOME/etc/system/local takes precedence over the same settings in $SPLUNK_HOME/etc/apps/*.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 23:45:03 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-09-29T23:45:03Z</dc:date>
    <item>
      <title>What takes precedence, index.conf on Universal Forwarder, or Forwarder Management</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-takes-precedence-index-conf-on-Universal-Forwarder-or/m-p/432898#M15326</link>
      <description>&lt;P&gt;I have just set up forwarder management, and I have noticed that while all my 'apps' are showing as deployed to my clients that have 'phoned home' and downloaded them, when I remote in to the UF machine(s). I am not seeing the updates from my 'inputs.conf' within my deployment server deployment-apps/{appName}/local/inputs.conf directory being reflected on the UF machine (web server) SplunkUniversalForwarder/etc/system/local/inputs.conf ... &lt;/P&gt;

&lt;P&gt;So, according to the forwarder manager the changes in my deployment-apps/{appName}/local/inputs.conf have been deployed to my client(s) without error. So, where, if anywhere, should I be seeing the inputs.conf changes on the UF box? Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 03:23:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-takes-precedence-index-conf-on-Universal-Forwarder-or/m-p/432898#M15326</guid>
      <dc:creator>kmower</dc:creator>
      <dc:date>2019-03-15T03:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: What takes precedence, index.conf on Universal Forwarder, or Forwarder Management</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-takes-precedence-index-conf-on-Universal-Forwarder-or/m-p/432899#M15327</link>
      <description>&lt;P&gt;The apps received from the deployment server will be found on the forwarders in the $SPLUNK_HOME/etc/apps directory.  Deployment servers cannot touch $SPLUNK_HOME/etc/system.&lt;/P&gt;

&lt;P&gt;To answer the question in subject line, $SPLUNK_HOME/etc/system/local takes precedence over the same settings in $SPLUNK_HOME/etc/apps/*.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:45:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-takes-precedence-index-conf-on-Universal-Forwarder-or/m-p/432899#M15327</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-09-29T23:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: What takes precedence, index.conf on Universal Forwarder, or Forwarder Management</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-takes-precedence-index-conf-on-Universal-Forwarder-or/m-p/432900#M15328</link>
      <description>&lt;P&gt;So, when setting up Forwarder Management, one should remove index.conf from the UF machine $SPLUNK_HOME/etc/system/local entirely? Thanks again.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Mar 2019 21:09:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-takes-precedence-index-conf-on-Universal-Forwarder-or/m-p/432900#M15328</guid>
      <dc:creator>kmower</dc:creator>
      <dc:date>2019-03-17T21:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: What takes precedence, index.conf on Universal Forwarder, or Forwarder Management</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-takes-precedence-index-conf-on-Universal-Forwarder-or/m-p/432901#M15329</link>
      <description>&lt;P&gt;Right, &lt;CODE&gt;$SPLUNK_HOME/etc/system/local/indexes.conf&lt;/CODE&gt; shouldn't exist on the UF.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Mar 2019 22:01:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-takes-precedence-index-conf-on-Universal-Forwarder-or/m-p/432901#M15329</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2019-03-17T22:01:59Z</dc:date>
    </item>
    <item>
      <title>Re: What takes precedence, index.conf on Universal Forwarder, or Forwarder Management</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-takes-precedence-index-conf-on-Universal-Forwarder-or/m-p/432902#M15330</link>
      <description>&lt;P&gt;Yeah, sorry. It is: C:\Program Files\SplunkUniversalForwarder\etc\system\local&lt;/P&gt;</description>
      <pubDate>Sun, 17 Mar 2019 23:38:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-takes-precedence-index-conf-on-Universal-Forwarder-or/m-p/432902#M15330</guid>
      <dc:creator>kmower</dc:creator>
      <dc:date>2019-03-17T23:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: What takes precedence, index.conf on Universal Forwarder, or Forwarder Management</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-takes-precedence-index-conf-on-Universal-Forwarder-or/m-p/432903#M15331</link>
      <description>&lt;P&gt;Put the contents of C:\Program Files\SplunkUniversalForwarder\etc\system\local into $SPLUNK_HOME\etc\deployment-apps\my_indexes\default\indexes.conf.  Delete C:\Program Files\SplunkUniversalForwarder\etc\system\local.  Add the my_indexes app to your UF server classes in Forwarder Management.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:45:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-takes-precedence-index-conf-on-Universal-Forwarder-or/m-p/432903#M15331</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-09-29T23:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: What takes precedence, index.conf on Universal Forwarder, or Forwarder Management</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-takes-precedence-index-conf-on-Universal-Forwarder-or/m-p/432904#M15332</link>
      <description>&lt;P&gt;OK, the entire C:\Program Files\SplunkUniversalForwarder\etc\system\local directory? Just move/delete it, even deploymentclient.conf which seems to wire it up for management by a deployment server? &lt;/P&gt;

&lt;P&gt;I have deleted inputs.conf and outputs.conf from the C:\Program Files\SplunkUniversalForwarder\etc\system\local restarted the service and even reloaded the deploy-server on the splunk indexer. Still only seeing the one W3SVC folder logs, and not even all of the files in there that are my ignoreOlderThan = 90d clause ... it is only grabbing the past week it seems.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 00:14:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-takes-precedence-index-conf-on-Universal-Forwarder-or/m-p/432904#M15332</guid>
      <dc:creator>kmower</dc:creator>
      <dc:date>2019-03-19T00:14:58Z</dc:date>
    </item>
    <item>
      <title>Re: What takes precedence, index.conf on Universal Forwarder, or Forwarder Management</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-takes-precedence-index-conf-on-Universal-Forwarder-or/m-p/432905#M15333</link>
      <description>&lt;P&gt;We're only discussing indexes.conf so only the file need be deleted from etc\system\local.&lt;BR /&gt;
When you deleted inputs.conf and outputs.conf from etc\system\local, did you replace them with files in an app?&lt;BR /&gt;
Do not reload deploy-server on an indexer - it must be done on the deployment server.  An indexer should never serve as a deployment server.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 12:46:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-takes-precedence-index-conf-on-Universal-Forwarder-or/m-p/432905#M15333</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-03-19T12:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: What takes precedence, index.conf on Universal Forwarder, or Forwarder Management</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-takes-precedence-index-conf-on-Universal-Forwarder-or/m-p/432906#M15334</link>
      <description>&lt;P&gt;Yes, thanks, that was it .... and a bit more. I did remove outputs.conf and inputs.conf from the Universal Forwarder machine. I have one 'master' app to push outputs.conf from my deployment server, while I have different flavor apps for inputs.conf. Once deployed those apps show up on the Universal Forwarder machines' etc/apps directories. &lt;/P&gt;

&lt;P&gt;However, I was still not getting all my iis logs across across. So, in the end I logged a support call with Splunk, and as it turns out: &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;The Windows Universal forwarder seems to ignore 'small' log files, and we have daily log files from iis; and&lt;/LI&gt;
&lt;LI&gt;There may have been an error with my other W3SVC directory logs - W3SVC2 where it wasn't escaping quotes properly and the Splunk indexer was throwing errors on those, so: &lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;I added to extra lines to my inputs.conf: &lt;/P&gt;

&lt;P&gt;initCrcLength = 2310&lt;BR /&gt;
alwaysOpenFile = 1&lt;/P&gt;

&lt;P&gt;This, along with placing a limits.conf file on the Universal Forwarder machine in C:\Program Files\SplunkUniversalForwarder\etc\system\local with the clause:&lt;/P&gt;

&lt;P&gt;[thruput]&lt;BR /&gt;
maxKBps = 0&lt;/P&gt;

&lt;P&gt;Has cleared my log forwarding constipation. Everything within my ingoreOlderThan = 90d is now coming through &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;

&lt;P&gt;Thanks again for the help.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 21:37:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-takes-precedence-index-conf-on-Universal-Forwarder-or/m-p/432906#M15334</guid>
      <dc:creator>kmower</dc:creator>
      <dc:date>2019-03-19T21:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: What takes precedence, index.conf on Universal Forwarder, or Forwarder Management</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-takes-precedence-index-conf-on-Universal-Forwarder-or/m-p/432907#M15335</link>
      <description>&lt;P&gt;Oh, yes, also note for the quote issue, and for changing GMT time to the Splunk Server's time settings I added these lines to props.conf on both the indexer and forwarer in etc/system/local/props.conf &lt;/P&gt;

&lt;P&gt;[iis]&lt;BR /&gt;
TIME_FORMAT = %Y-%m-%d %H:%M:%S&lt;BR /&gt;
TZ = GMT&lt;BR /&gt;
FIELD_QUOTE = none&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:44:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-takes-precedence-index-conf-on-Universal-Forwarder-or/m-p/432907#M15335</guid>
      <dc:creator>kmower</dc:creator>
      <dc:date>2020-09-29T23:44:02Z</dc:date>
    </item>
  </channel>
</rss>

