<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can we clone the HF to another one? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Can-we-clone-the-HF-to-another-one/m-p/703789#M238506</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/270634"&gt;@Vnarunart&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;yes, you can clone the old HF to a new one but, in addition, remember to change also the hostname in $SPLUNK_HOME/etc/system/loca/server.conf and&amp;nbsp;$SPLUNK_HOME/etc/system/loca/inputs.conf.&lt;/P&gt;&lt;P&gt;Anyway, having a Deployment Server, you could create a new Splunk installation and manage both the HFs with the DS deploying the same apps.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 07 Nov 2024 10:22:46 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2024-11-07T10:22:46Z</dc:date>
    <item>
      <title>Can we clone the HF to another one?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-we-clone-the-HF-to-another-one/m-p/703783#M238505</link>
      <description>&lt;P&gt;I would like to seek advice from experienced professionals. I want to add another heavy forwarder to my environment as a backup in case the primary one fails (on a different network and not necessarily active-active).&amp;nbsp; * I have splunk cloud and 1 Heavy Forwarder, 1&amp;nbsp; Deployment server on premise.&lt;/P&gt;&lt;P&gt;1. If I copy a heavy forwarder (VM) from one vCenter to another, change the IP, and generate new credentials from Splunk Cloud, will it work immediately? (I want to preserve my existing configurations.)&lt;BR /&gt;2. I have a deployment server. Can I use it to configure two heavy forwarders? If so, what would be the implications? (Would there be data duplication, or is there a way to prioritize data?&lt;/P&gt;&lt;P&gt;Or is there a better way I should do this? Please advise.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2024 09:34:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-we-clone-the-HF-to-another-one/m-p/703783#M238505</guid>
      <dc:creator>Vnarunart</dc:creator>
      <dc:date>2024-11-07T09:34:37Z</dc:date>
    </item>
    <item>
      <title>Re: Can we clone the HF to another one?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-we-clone-the-HF-to-another-one/m-p/703789#M238506</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/270634"&gt;@Vnarunart&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;yes, you can clone the old HF to a new one but, in addition, remember to change also the hostname in $SPLUNK_HOME/etc/system/loca/server.conf and&amp;nbsp;$SPLUNK_HOME/etc/system/loca/inputs.conf.&lt;/P&gt;&lt;P&gt;Anyway, having a Deployment Server, you could create a new Splunk installation and manage both the HFs with the DS deploying the same apps.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2024 10:22:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-we-clone-the-HF-to-another-one/m-p/703789#M238506</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-11-07T10:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: Can we clone the HF to another one?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-we-clone-the-HF-to-another-one/m-p/703868#M238537</link>
      <description>&lt;P&gt;Thank you very much for your comprehensive response. I have a follow-up question. In a scenario where we have two HF, is there a way to determine which HF the data originated from when searching in Splunk Cloud?&lt;/P&gt;&lt;P&gt;Thank you for your advice and time.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 03:10:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-we-clone-the-HF-to-another-one/m-p/703868#M238537</guid>
      <dc:creator>Vnarunart</dc:creator>
      <dc:date>2024-11-08T03:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: Can we clone the HF to another one?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-we-clone-the-HF-to-another-one/m-p/703888#M238551</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/270634"&gt;@Vnarunart&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;this is a request that I posted in Splunk Ideas (&lt;A href="https://ideas.splunk.com/ideas/EID-I-1731" target="_blank"&gt;https://ideas.splunk.com/ideas/EID-I-1731&lt;/A&gt;) and it's in "Under consideration" state, if you think that's useful, please vote it!&lt;/P&gt;&lt;P&gt;Anyway, you could add to your Heavy forwarders a custom field with the name of the HF:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.2.2403/Data/Configureindex-timefieldextraction" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/9.2.2403/Data/Configureindex-timefieldextraction&lt;/A&gt;&lt;/P&gt;&lt;P&gt;in props.conf&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[default]
TRANSFORMS-hf_name = my_hf_1&lt;/LI-CODE&gt;&lt;P&gt;in props.conf:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[my_hf_1]
REGEX = .
FORMAT = my_hf_1::my_hf_1
WRITE_META = [true]
DEST_KEY = my_hf_1
DEFAULT_VALUE = my_hf_1&lt;/LI-CODE&gt;&lt;P&gt;and then in fields.conf&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[my_hf_1]
INDEXED=true&lt;/LI-CODE&gt;&lt;P&gt;one for each HF.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 07:35:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-we-clone-the-HF-to-another-one/m-p/703888#M238551</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-11-08T07:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: Can we clone the HF to another one?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-we-clone-the-HF-to-another-one/m-p/703895#M238553</link>
      <description>&lt;P&gt;I appreciate your advice.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 08:46:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-we-clone-the-HF-to-another-one/m-p/703895#M238553</guid>
      <dc:creator>Vnarunart</dc:creator>
      <dc:date>2024-11-08T08:46:21Z</dc:date>
    </item>
    <item>
      <title>Re: Can we clone the HF to another one?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-we-clone-the-HF-to-another-one/m-p/703897#M238554</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/270634"&gt;@Vnarunart&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;let me know if I can help you more, or, please, accept one answer for the other people of Community.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 08:47:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-we-clone-the-HF-to-another-one/m-p/703897#M238554</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-11-08T08:47:09Z</dc:date>
    </item>
  </channel>
</rss>

