<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to dynamically add servers to serverclass.conf Whitelist in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-dynamically-add-servers-to-serverclass-conf-Whitelist/m-p/254001#M15877</link>
    <description>&lt;P&gt;we have ~16,000 windows client machines  and  the machines are reporting to a app &lt;BR /&gt;
[serverClass:xom_TA-app1]&lt;BR /&gt;
whitelist.0 = windows&lt;BR /&gt;
machineTypesFilter = windows-intel,windows-x64&lt;/P&gt;

&lt;P&gt;now we want to split  ~1,500 point to app2 and the rest of 14,500 to point to app1 &lt;/P&gt;

&lt;P&gt;how can we achieve this without adding all the server names to whitelist as it will be very painful to manage? &lt;/P&gt;</description>
    <pubDate>Wed, 25 Jan 2017 21:58:36 GMT</pubDate>
    <dc:creator>muthu285kumar</dc:creator>
    <dc:date>2017-01-25T21:58:36Z</dc:date>
    <item>
      <title>How to dynamically add servers to serverclass.conf Whitelist</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-dynamically-add-servers-to-serverclass-conf-Whitelist/m-p/254001#M15877</link>
      <description>&lt;P&gt;we have ~16,000 windows client machines  and  the machines are reporting to a app &lt;BR /&gt;
[serverClass:xom_TA-app1]&lt;BR /&gt;
whitelist.0 = windows&lt;BR /&gt;
machineTypesFilter = windows-intel,windows-x64&lt;/P&gt;

&lt;P&gt;now we want to split  ~1,500 point to app2 and the rest of 14,500 to point to app1 &lt;/P&gt;

&lt;P&gt;how can we achieve this without adding all the server names to whitelist as it will be very painful to manage? &lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 21:58:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-dynamically-add-servers-to-serverclass-conf-Whitelist/m-p/254001#M15877</guid>
      <dc:creator>muthu285kumar</dc:creator>
      <dc:date>2017-01-25T21:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to dynamically add servers to serverclass.conf Whitelist</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-dynamically-add-servers-to-serverclass-conf-Whitelist/m-p/254002#M15878</link>
      <description>&lt;P&gt;Unfortunately the deployment server can only filter by os and hostname. If your environment has strict naming conventions (which is probably not the cas if you have that many hosts) you can use patterns in the whitelist filters, eg &lt;CODE&gt;whitelist.0  = web[1-8]&lt;/CODE&gt; , but otherwise you will have to put each row in there manually. There's a few ways you can do it outside of Splunk, for example we generate the serverclass.conf via script by querying an LDAP directory and generating serverclasses based on OU membership. &lt;/P&gt;

&lt;P&gt;However, for a large fleet of windows clients, I'm guessing you want to capture the windows event logs. If so, you might  investigate using the Windows Event Collector service (an MS Server Role) to collect all the logs from the endpoints, and then have universal forwarders running on your WEC hosts. &lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 11:29:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-dynamically-add-servers-to-serverclass-conf-Whitelist/m-p/254002#M15878</guid>
      <dc:creator>jplumsdaine22</dc:creator>
      <dc:date>2017-01-26T11:29:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to dynamically add servers to serverclass.conf Whitelist</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-dynamically-add-servers-to-serverclass-conf-Whitelist/m-p/254003#M15879</link>
      <description>&lt;P&gt;@muthu285kumar - Did the answer provided by jplumsdaine22 help provide a solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 12 Feb 2017 04:33:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-dynamically-add-servers-to-serverclass-conf-Whitelist/m-p/254003#M15879</guid>
      <dc:creator>aaraneta_splunk</dc:creator>
      <dc:date>2017-02-12T04:33:51Z</dc:date>
    </item>
  </channel>
</rss>

