<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Introducing Splunk DS to an existing Splunk environment in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Introducing-Splunk-DS-to-an-existing-Splunk-environment/m-p/519733#M6670</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/120233"&gt;@varad_joshi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I have two main hints before starting this job:&lt;/P&gt;&lt;P&gt;1) make a very accurate planning of your Serverclasses:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;in other words, create in Excel (or something similar) a list of you servers, listing the TAs (Technical Add-Ons) to deploy in each one;&lt;/LI&gt;&lt;LI&gt;then think to the serverClasses to implement: a ServerClass is a table that make an association between a group of server (with the same TA to deploy) and the TAs to deploy.&lt;/LI&gt;&lt;/UL&gt;&lt;P class="lia-indent-padding-left-30px"&gt;This operation is very very important to avoid to have too many ServerClasses and heavy management..&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Remember that the apps non listed in ServerClasses will be deleted from the servers!&lt;/P&gt;&lt;P&gt;2) create at least one TA (called e.g. TA_Forwarders) that contain only three files:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;apps.conf (describing the app)&lt;/LI&gt;&lt;LI&gt;outputs.conf (containing the addressing of the indexers to send data);&lt;/LI&gt;&lt;LI&gt;deploymentclient.conf (contaioning the address of the Deployment Server).&lt;/LI&gt;&lt;/UL&gt;&lt;P class="lia-indent-padding-left-30px"&gt;the number of TA_Forwarders depends on your architecture: you need at least one TA, but you could have more of them if you have Heavy Forwarders as concentrators.&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;If possible, delete (e.g. using a script) the actual outputs.conf.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Tue, 15 Sep 2020 14:56:39 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2020-09-15T14:56:39Z</dc:date>
    <item>
      <title>Introducing Splunk DS to an existing Splunk environment</title>
      <link>https://community.splunk.com/t5/Installation/Introducing-Splunk-DS-to-an-existing-Splunk-environment/m-p/519693#M6669</link>
      <description>&lt;P&gt;We have an existing environment with 100+ servers sending data to IDX. We never had a DS before and now we want to introduce DS so that it's easier to manage the client.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What are the things I consider before I start planning? Which config files I should be worried about getting overwritten when I add the existing UF as client to my DS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 13:36:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Introducing-Splunk-DS-to-an-existing-Splunk-environment/m-p/519693#M6669</guid>
      <dc:creator>varad_joshi</dc:creator>
      <dc:date>2020-09-15T13:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: Introducing Splunk DS to an existing Splunk environment</title>
      <link>https://community.splunk.com/t5/Installation/Introducing-Splunk-DS-to-an-existing-Splunk-environment/m-p/519733#M6670</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/120233"&gt;@varad_joshi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I have two main hints before starting this job:&lt;/P&gt;&lt;P&gt;1) make a very accurate planning of your Serverclasses:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;in other words, create in Excel (or something similar) a list of you servers, listing the TAs (Technical Add-Ons) to deploy in each one;&lt;/LI&gt;&lt;LI&gt;then think to the serverClasses to implement: a ServerClass is a table that make an association between a group of server (with the same TA to deploy) and the TAs to deploy.&lt;/LI&gt;&lt;/UL&gt;&lt;P class="lia-indent-padding-left-30px"&gt;This operation is very very important to avoid to have too many ServerClasses and heavy management..&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Remember that the apps non listed in ServerClasses will be deleted from the servers!&lt;/P&gt;&lt;P&gt;2) create at least one TA (called e.g. TA_Forwarders) that contain only three files:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;apps.conf (describing the app)&lt;/LI&gt;&lt;LI&gt;outputs.conf (containing the addressing of the indexers to send data);&lt;/LI&gt;&lt;LI&gt;deploymentclient.conf (contaioning the address of the Deployment Server).&lt;/LI&gt;&lt;/UL&gt;&lt;P class="lia-indent-padding-left-30px"&gt;the number of TA_Forwarders depends on your architecture: you need at least one TA, but you could have more of them if you have Heavy Forwarders as concentrators.&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;If possible, delete (e.g. using a script) the actual outputs.conf.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 14:56:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Introducing-Splunk-DS-to-an-existing-Splunk-environment/m-p/519733#M6670</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-15T14:56:39Z</dc:date>
    </item>
  </channel>
</rss>

