<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Enterprise &amp; UF on the same machine in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enterprise-UF-on-the-same-machine/m-p/486859#M83370</link>
    <description>&lt;P&gt;@codebuilder the majority are windows event logs, any ideas on how to archive them?&lt;/P&gt;</description>
    <pubDate>Thu, 30 Apr 2020 10:27:09 GMT</pubDate>
    <dc:creator>andresito123</dc:creator>
    <dc:date>2020-04-30T10:27:09Z</dc:date>
    <item>
      <title>Splunk Enterprise &amp; UF on the same machine</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enterprise-UF-on-the-same-machine/m-p/486856#M83367</link>
      <description>&lt;P&gt;I have inherited a Splunk installation from the previous administrator where there is a heavy forwarder &lt;STRONG&gt;and&lt;/STRONG&gt; a UF installed on the same machine. &lt;/P&gt;

&lt;P&gt;Since this is a bad practice in terms of performance, I am planning to remove the UF and copy the relevant inputs files to the Splunk Enterprise instance (which acts as a heavy forwarder).&lt;/P&gt;

&lt;P&gt;How can I avoid re-indexing the same logs when copying the inputs configuration from the HF to the UF (mainly Windows Events)?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2020 13:37:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enterprise-UF-on-the-same-machine/m-p/486856#M83367</guid>
      <dc:creator>andresito123</dc:creator>
      <dc:date>2020-04-24T13:37:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise &amp; UF on the same machine</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enterprise-UF-on-the-same-machine/m-p/486857#M83368</link>
      <description>&lt;P&gt;There are multiple methods you can use to solve this. Below are a few (all will involve first stopping the UF):&lt;/P&gt;

&lt;P&gt;Rename the existing directory, then re-create it, and configure the HF to monitor.&lt;/P&gt;

&lt;P&gt;Archive/compress the existing files and blacklist that file extension (.zip, .gz, etc.) on the HF.&lt;/P&gt;

&lt;P&gt;If your existing files contain a timestamp in the file name, blacklist anything older than when you made the cut over from UF to HF.&lt;/P&gt;

&lt;P&gt;Opposite of the above, whitelist any file with a timestamp newer than when you make the change.&lt;/P&gt;

&lt;P&gt;Those are a few ideas, but again there are multiple ways to accomplish this.&lt;BR /&gt;
This documentation may help as well: &lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.3/Data/Whitelistorblacklistspecificincomingdata"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.3/Data/Whitelistorblacklistspecificincomingdata&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2020 23:52:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enterprise-UF-on-the-same-machine/m-p/486857#M83368</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2020-04-24T23:52:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise &amp; UF on the same machine</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enterprise-UF-on-the-same-machine/m-p/486858#M83369</link>
      <description>&lt;P&gt;ok thanks, those workarounds make sense!&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 09:48:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enterprise-UF-on-the-same-machine/m-p/486858#M83369</guid>
      <dc:creator>andresito123</dc:creator>
      <dc:date>2020-04-27T09:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise &amp; UF on the same machine</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enterprise-UF-on-the-same-machine/m-p/486859#M83370</link>
      <description>&lt;P&gt;@codebuilder the majority are windows event logs, any ideas on how to archive them?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2020 10:27:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enterprise-UF-on-the-same-machine/m-p/486859#M83370</guid>
      <dc:creator>andresito123</dc:creator>
      <dc:date>2020-04-30T10:27:09Z</dc:date>
    </item>
  </channel>
</rss>

