Deployment Architecture

Can you reference clientName from other .conf files?

devenjarvis
Path Finder

Hello,

We are planning a deployment using a Splunk Deployment Server, for 80+ UF. We are hoping to push inputs.conf, outputs.conf, and server.conf to these serves. However, outputs.conf and server.conf have references that are unique to that UF's servername. For instance one forwarder may have a servername of server1, and the next be server2, and so on until server80.

The simplest example would then be the host set in the server.conf file: Could this be equal to 'server1' or 'server2' or 'server80' based on which server it is on? My thought was when we first setup the deploymentclient.conf file for each forwarder we would set the clientName to it's server name - however I don't know if there is a way to reference to this clientName for another .conf file.

Any other suggestions to achieve what we are looking for would be very welcome!

Thanks,
Deven

0 Karma

woodcock
Esteemed Legend

You do not need to reference the clientName in other files. What you need to do is create 80 custom serverclasses, each with a custom app, each with a set of custom .conf files. Then, when the UF checks in with the DS, the DS will use the clientname to match it and boom, off you go.

0 Karma

somesoni2
SplunkTrust
SplunkTrust

There will be default version of server.conf file gets created after first start of UF in the location $Splunk_Home/etc/system/local which will have the server name already. Check that file on the forwarder and you probably don't need to include that in the app that you're planning to push.

0 Karma
Get Updates on the Splunk Community!

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...