<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: If we clone a Windows server with a Splunk forwarder installed, how do we configure the the cloned server to send data to Splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/If-we-clone-a-Windows-server-with-a-Splunk-forwarder-installed/m-p/239246#M46501</link>
    <description>&lt;P&gt;Thank you, I will try that!&lt;/P&gt;</description>
    <pubDate>Thu, 19 Nov 2015 18:09:21 GMT</pubDate>
    <dc:creator>omuelle1</dc:creator>
    <dc:date>2015-11-19T18:09:21Z</dc:date>
    <item>
      <title>If we clone a Windows server with a Splunk forwarder installed, how do we configure the the cloned server to send data to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-we-clone-a-Windows-server-with-a-Splunk-forwarder-installed/m-p/239242#M46497</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;

&lt;P&gt;I think this is a rather silly question, but I haven't been working with Splunk for too long and just can't figure it out.&lt;/P&gt;

&lt;P&gt;We just cloned a Windows box (server1) that has a Splunk forwarder installed that is sending data to Splunk. The clone: server2 has everything server1 had, including the Splunk Forwarder. My question is, how to get the Server2 talking to Splunk and sending Data to Splunk? I cannot locate a file where IPs/Hostnames of Forwarding servers are configured.&lt;/P&gt;

&lt;P&gt;When I check under Forwarder Management in the SPLUNK UI, Server2 isn't even being recognized.&lt;/P&gt;

&lt;P&gt;Oliver&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2015 16:29:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-we-clone-a-Windows-server-with-a-Splunk-forwarder-installed/m-p/239242#M46497</guid>
      <dc:creator>omuelle1</dc:creator>
      <dc:date>2015-11-18T16:29:30Z</dc:date>
    </item>
    <item>
      <title>Re: If we clone a Windows server with a Splunk forwarder installed, how do we configure the the cloned server to send data to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-we-clone-a-Windows-server-with-a-Splunk-forwarder-installed/m-p/239243#M46498</link>
      <description>&lt;P&gt;It did not show up however, I am suspecting it has to do with the server.conf file on the cloned server.&lt;/P&gt;

&lt;P&gt;On the cloned server I have exactly the same server,conf file under system/local  with the same generated key. Might this be the problem why it couldn't be recognized on the DS ?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2015 14:17:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-we-clone-a-Windows-server-with-a-Splunk-forwarder-installed/m-p/239243#M46498</guid>
      <dc:creator>omuelle1</dc:creator>
      <dc:date>2015-11-19T14:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: If we clone a Windows server with a Splunk forwarder installed, how do we configure the the cloned server to send data to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-we-clone-a-Windows-server-with-a-Splunk-forwarder-installed/m-p/239244#M46499</link>
      <description>&lt;P&gt;Ideally you want to run the "./splunk clone-prep-clear-config" command as referenced in the &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.1/Forwarding/Makeadfpartofasystemimage"&gt;Splunk documentation&lt;/A&gt; before cloning the server. You can reference &lt;A href="https://answers.splunk.com/answers/32368/duplicate-guids-for-cloned-forwarders-how-to-correct.html"&gt;this answer&lt;/A&gt; to get an idea how to clean up the servername/GUID on the existing clone to get it to generate a new one.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2015 17:23:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-we-clone-a-Windows-server-with-a-Splunk-forwarder-installed/m-p/239244#M46499</guid>
      <dc:creator>bdahlb</dc:creator>
      <dc:date>2015-11-19T17:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: If we clone a Windows server with a Splunk forwarder installed, how do we configure the the cloned server to send data to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-we-clone-a-Windows-server-with-a-Splunk-forwarder-installed/m-p/239245#M46500</link>
      <description>&lt;P&gt;Ideally you want to run the "./splunk clone-prep-clear-config" command as referenced in the Splunk documentation "&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.1/Forwarding/Makeadfpartofasystemimage"&gt;http://docs.splunk.com/Documentation/Splunk/6.3.1/Forwarding/Makeadfpartofasystemimage&lt;/A&gt;" before cloning the server. You can reference this answer "&lt;A href="https://answers.splunk.com/answers/32368/duplicate-guids-for-cloned-forwarders-how-to-correct.html"&gt;https://answers.splunk.com/answers/32368/duplicate-guids-for-cloned-forwarders-how-to-correct.html&lt;/A&gt;" to get an idea how to clean up the servername/GUID on the existing clone to get it to generate a new one.&lt;/P&gt;

&lt;P&gt;Edit: Hurray for links not working for me!&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2015 17:26:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-we-clone-a-Windows-server-with-a-Splunk-forwarder-installed/m-p/239245#M46500</guid>
      <dc:creator>bdahlb</dc:creator>
      <dc:date>2015-11-19T17:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: If we clone a Windows server with a Splunk forwarder installed, how do we configure the the cloned server to send data to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-we-clone-a-Windows-server-with-a-Splunk-forwarder-installed/m-p/239246#M46501</link>
      <description>&lt;P&gt;Thank you, I will try that!&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2015 18:09:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-we-clone-a-Windows-server-with-a-Splunk-forwarder-installed/m-p/239246#M46501</guid>
      <dc:creator>omuelle1</dc:creator>
      <dc:date>2015-11-19T18:09:21Z</dc:date>
    </item>
  </channel>
</rss>

