<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to repoint the UF to the newly added forwarder in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-repoint-the-UF-to-the-newly-added-forwarder/m-p/640770#M27077</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249495"&gt;@Rakzskull&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;&amp;nbsp;and &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;hinted you have to update both deploymentclient.conf and outputs.conf.&lt;/P&gt;&lt;P&gt;My hint is to create a new add-on (called e.g. TA_Forwarders), containing at least three files:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;apps.conf: describing the add-on,&lt;/LI&gt;&lt;LI&gt;outputs.conf: addressing the HFs or the Indexers to send data,&lt;/LI&gt;&lt;LI&gt;deploymentclient.conf: addressing the Deployment Server.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;in this way you can centrally manage your Universal Forwarders without locally intervene on the machines.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 20 Apr 2023 08:15:53 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-04-20T08:15:53Z</dc:date>
    <item>
      <title>How to repoint the UF to the newly added forwarder?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-repoint-the-UF-to-the-newly-added-forwarder/m-p/640757#M27074</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I deployed a new heavy forwarder in our environment, however I'd want to repoint certain devices to the freshly deployed forwarder. I tried updating the ip in the local/deploymentclient.conf, but I'm still getting the old HF information in logs.&lt;/P&gt;
&lt;P&gt;Could you demonstrate to me how to do so?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 16:38:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-repoint-the-UF-to-the-newly-added-forwarder/m-p/640757#M27074</guid>
      <dc:creator>Rakzskull</dc:creator>
      <dc:date>2023-04-20T16:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to repoint the UF to the newly added forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-repoint-the-UF-to-the-newly-added-forwarder/m-p/640760#M27075</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249495"&gt;@Rakzskull&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You must update outputs.conf in your UF to send logs to new HF.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Editing deploymentclient.conf only changes the deployment server address. If you are using deployment server to manage UF's you should update related deployment app outputs.conf configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 07:49:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-repoint-the-UF-to-the-newly-added-forwarder/m-p/640760#M27075</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2023-04-20T07:49:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to repoint the UF to the newly added forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-repoint-the-UF-to-the-newly-added-forwarder/m-p/640762#M27076</link>
      <description>&lt;P&gt;I suppose that you have own (probably several) app for UF base configuration? Just copy it and change its outputs.conf to point that IHF to send events there. Then switch that app to correct UFs on DS side.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 07:53:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-repoint-the-UF-to-the-newly-added-forwarder/m-p/640762#M27076</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-04-20T07:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to repoint the UF to the newly added forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-repoint-the-UF-to-the-newly-added-forwarder/m-p/640770#M27077</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249495"&gt;@Rakzskull&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;&amp;nbsp;and &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;hinted you have to update both deploymentclient.conf and outputs.conf.&lt;/P&gt;&lt;P&gt;My hint is to create a new add-on (called e.g. TA_Forwarders), containing at least three files:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;apps.conf: describing the add-on,&lt;/LI&gt;&lt;LI&gt;outputs.conf: addressing the HFs or the Indexers to send data,&lt;/LI&gt;&lt;LI&gt;deploymentclient.conf: addressing the Deployment Server.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;in this way you can centrally manage your Universal Forwarders without locally intervene on the machines.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 08:15:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-repoint-the-UF-to-the-newly-added-forwarder/m-p/640770#M27077</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-04-20T08:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to repoint the UF to the newly added forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-repoint-the-UF-to-the-newly-added-forwarder/m-p/640784#M27080</link>
      <description>&lt;P&gt;The local config directory of the UF’s does not contain outputs.conf file. I can only see below files in&amp;nbsp;&amp;nbsp;opt/splunk/etc/system/local&amp;nbsp;&lt;/P&gt;&lt;P&gt;deploymentclient.conf&lt;/P&gt;&lt;P&gt;inputs.conf&lt;/P&gt;&lt;P&gt;migration.conf&lt;/P&gt;&lt;P&gt;server.conf&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 09:21:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-repoint-the-UF-to-the-newly-added-forwarder/m-p/640784#M27080</guid>
      <dc:creator>Rakzskull</dc:creator>
      <dc:date>2023-04-20T09:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to repoint the UF to the newly added forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-repoint-the-UF-to-the-newly-added-forwarder/m-p/640785#M27081</link>
      <description>&lt;P&gt;Probably you have some apps installed on your UF. Those should be on /opt/splunkforwarder/etc/apps directory. The easiest way to look what you have on outputs.conf and where is use command&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;PATH TO YOUR SPLUNK UF HOME&amp;gt;/bin/splunk btool outputs list --debug&lt;/LI-CODE&gt;&lt;P&gt;That shows all attributes with values and where those are defined.&lt;/P&gt;&lt;P&gt;Is your conf from IHF instead of UF (based on path /opt/splunk instead of /opt/splunkforwarder)?&lt;/P&gt;&lt;P&gt;Anyhow as &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;said you should have own app for UF (I prefer several based on needs on your environment) base configurations. On that app you have configurations for where to send events (outputs.conf). Then this can contains also DS configurations or that can be on separate app, it's depending on your environment and needs.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 09:29:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-repoint-the-UF-to-the-newly-added-forwarder/m-p/640785#M27081</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-04-20T09:29:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to repoint the UF to the newly added forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-repoint-the-UF-to-the-newly-added-forwarder/m-p/640847#M27083</link>
      <description>&lt;P&gt;One more thing: just out of curiosity, I changed the output.conf file with the new HF IP.&lt;/P&gt;&lt;P&gt;Is it necessary to also change the same HF IP in&amp;nbsp; the deploymentclient.conf ?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 15:05:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-repoint-the-UF-to-the-newly-added-forwarder/m-p/640847#M27083</guid>
      <dc:creator>Rakzskull</dc:creator>
      <dc:date>2023-04-20T15:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to repoint the UF to the newly added forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-repoint-the-UF-to-the-newly-added-forwarder/m-p/640848#M27084</link>
      <description>&lt;P&gt;No, DS is just for deploy those configurations to UF. Outputs.conf define where UF will send events. Those are different hosts in almost all not single node environments.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 15:12:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-repoint-the-UF-to-the-newly-added-forwarder/m-p/640848#M27084</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-04-20T15:12:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to repoint the UF to the newly added forwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-repoint-the-UF-to-the-newly-added-forwarder/m-p/640944#M27085</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249495"&gt;@Rakzskull&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;no as me and&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;said in deploymentclient.conf there's the address of the Deployment Server, the server with the role to manage forwarders, instead in outputs.conf there's the address of Indexers or Heavy Forwarders that muste receive logs from the UF.&lt;/P&gt;&lt;P&gt;They can be the same server in labs or little infrastructure, nevere in medium or big deployments, because in this case both Indexers and Deployment Server must be in dedicated servers, so they have diferent IPs.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 07:09:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-repoint-the-UF-to-the-newly-added-forwarder/m-p/640944#M27085</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-04-21T07:09:58Z</dc:date>
    </item>
  </channel>
</rss>

