<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I enable both Splunk server and Splunk Universal Forwarder at boot time? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201258#M39809</link>
    <description>&lt;P&gt;You do not need to install Universal Forwarder on the Splunk server, but you do need to install it on each Windows client.&lt;/P&gt;</description>
    <pubDate>Tue, 08 Nov 2016 11:15:32 GMT</pubDate>
    <dc:creator>ehudb</dc:creator>
    <dc:date>2016-11-08T11:15:32Z</dc:date>
    <item>
      <title>How can I enable both Splunk server and Splunk Universal Forwarder at boot time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201251#M39802</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm setting up a server with both splunk-server and splunk-universal-forwarder.&lt;BR /&gt;
When I try to enable the splunk-server service at boot time with this command:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sudo /opt/splunk/bin/splunk enable boot-start -user root
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;everything is ok and the /etc/init.d/splunk file is created&lt;/P&gt;

&lt;P&gt;But when I try to enable the splunk-universal-forwarder service at boot time, I got this output:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sudo /opt/splunkforwarder/bin/splunk enable boot-start -user root
 System start/stop links for /etc/init.d/splunk already exist.
Init script installed at /etc/init.d/splunk.
Init script is configured to run at boot.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And the existing /etc/init.d/splunk file is replaced by the new one.&lt;/P&gt;

&lt;P&gt;So in the end, I can only enable one service at a time but I'd like to enable both of them of course.&lt;BR /&gt;
Thanking you in advance for your help&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Vincent.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2016 14:25:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201251#M39802</guid>
      <dc:creator>vincent_deygas</dc:creator>
      <dc:date>2016-11-01T14:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: How can I enable both Splunk server and Splunk Universal Forwarder at boot time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201252#M39803</link>
      <description>&lt;P&gt;You cannot and do not need universal forwarder and full instance on the same server.&lt;/P&gt;

&lt;P&gt;The full instance can provide full forwarder functionality, so you can use it to collect whatever you need.&lt;BR /&gt;
Just configure inputs\props or forwarder apps like you would do with universal forwarder.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2016 15:09:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201252#M39803</guid>
      <dc:creator>ehudb</dc:creator>
      <dc:date>2016-11-01T15:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: How can I enable both Splunk server and Splunk Universal Forwarder at boot time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201253#M39804</link>
      <description>&lt;P&gt;Interesting thing. For some reason both commands attempt to create the &lt;CODE&gt;/etc/init.d/splunk&lt;/CODE&gt; file. Looks like a bug ; -)&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2016 22:22:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201253#M39804</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-11-01T22:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: How can I enable both Splunk server and Splunk Universal Forwarder at boot time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201254#M39805</link>
      <description>&lt;P&gt;I believe the Splunk Enterprise holds a Heavy Forwarder but not a Universal one. So maybe @vincent_deygas can you the Heavy Forwarder instead...&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2016 22:23:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201254#M39805</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-11-01T22:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: How can I enable both Splunk server and Splunk Universal Forwarder at boot time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201255#M39806</link>
      <description>&lt;P&gt;Hello, I am new to using this software and just installed Splunk Enterprise and want to monitor events logs from Windows hosts on the network. My question is, is it necessary to install the Universal Forwarder to make this happen? There is a ton of documents out there but it can be very confusing especially when new to the software. Any help would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 20:34:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201255#M39806</guid>
      <dc:creator>larryholbert</dc:creator>
      <dc:date>2016-11-07T20:34:21Z</dc:date>
    </item>
    <item>
      <title>Re: How can I enable both Splunk server and Splunk Universal Forwarder at boot time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201256#M39807</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;
The universal forwarder is acting as an "agnet", it's just collecting  local data (events) , and moving them forward to full splunk instance.&lt;/P&gt;

&lt;P&gt;You would need 1 splunk full instance and a universal forwarder on each of the desired windows servers (which you want events from)&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 21:23:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201256#M39807</guid>
      <dc:creator>ehudb</dc:creator>
      <dc:date>2016-11-07T21:23:52Z</dc:date>
    </item>
    <item>
      <title>Re: How can I enable both Splunk server and Splunk Universal Forwarder at boot time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201257#M39808</link>
      <description>&lt;P&gt;thanks for the response ahudb. I have Windows clients that I would like to collect event logs from, If I have a full instance of Splunk Enterprise running on one server, do I need to install the Universal Forwarder on the Splunk Server?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2016 11:12:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201257#M39808</guid>
      <dc:creator>larryholbert</dc:creator>
      <dc:date>2016-11-08T11:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: How can I enable both Splunk server and Splunk Universal Forwarder at boot time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201258#M39809</link>
      <description>&lt;P&gt;You do not need to install Universal Forwarder on the Splunk server, but you do need to install it on each Windows client.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2016 11:15:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201258#M39809</guid>
      <dc:creator>ehudb</dc:creator>
      <dc:date>2016-11-08T11:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: How can I enable both Splunk server and Splunk Universal Forwarder at boot time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201259#M39810</link>
      <description>&lt;P&gt;Is there a way to push the universal forwarder out to all clients using Splunk Web? What is the most proficient way to do this?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2016 11:32:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201259#M39810</guid>
      <dc:creator>larryholbert</dc:creator>
      <dc:date>2016-11-08T11:32:44Z</dc:date>
    </item>
    <item>
      <title>Re: How can I enable both Splunk server and Splunk Universal Forwarder at boot time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201260#M39811</link>
      <description>&lt;P&gt;No, the Splunk deployment server can be used to manage universal forwarder configuration but you will need to use a form of automation to install the Splunk universal forwarder on your various endpoints.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2016 23:24:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201260#M39811</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2016-11-09T23:24:33Z</dc:date>
    </item>
    <item>
      <title>Re: How can I enable both Splunk server and Splunk Universal Forwarder at boot time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201261#M39812</link>
      <description>&lt;P&gt;Its not a bug, its just the script or both try to create a file in /etc/init.d/ with the same details.&lt;/P&gt;

&lt;P&gt;I get around it like this when I have two splunk instances on the same box:&lt;/P&gt;

&lt;P&gt;nano /etc/init.d/splunk&lt;BR /&gt;
edit this line:&lt;BR /&gt;
"# Provides: splunkd"     - Change splunkd to anything else. Useful might be ‘splunkdeploy’&lt;BR /&gt;
Rename the file&lt;BR /&gt;
mv /etc/init.d/splunk /etc/init.d/splunkdeploy&lt;BR /&gt;
set perms to 755 on the script file.&lt;BR /&gt;
chmod 755 /etc/init.d/splunkdeploy &lt;BR /&gt;
chkconfig --add splunkdeploy – to fix symbolic links and other magic.&lt;/P&gt;

&lt;P&gt;THEN run the second ‘enable boot-start’ command. It should go without a hitch.&lt;BR /&gt;
sudo /opt/splunksearch/splunk/bin/splunk enable boot-start -user splunksearch&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2016 03:03:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201261#M39812</guid>
      <dc:creator>mrgibbon</dc:creator>
      <dc:date>2016-11-10T03:03:09Z</dc:date>
    </item>
    <item>
      <title>Re: How can I enable both Splunk server and Splunk Universal Forwarder at boot time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201262#M39813</link>
      <description>&lt;P&gt;Hi @vincent_deygas - Looks like you have a few good options below to try. Did any one of the below answers work for you? If yes, please don't forget to click "Accept" before the best answer and up-vote any comments that were helpful. If no, please leave a comment to provide some feedback. Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2016 00:01:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-enable-both-Splunk-server-and-Splunk-Universal/m-p/201262#M39813</guid>
      <dc:creator>aaraneta_splunk</dc:creator>
      <dc:date>2016-11-16T00:01:55Z</dc:date>
    </item>
  </channel>
</rss>

