Deployment Architecture

Changing Indexer IP in Univerisal Forwader

sumit29
Path Finder

Hi All,

I need help , We have installed universal forwarder in around 20 machines and provided the deployment , Indexder IP . Logs are forwarder to the test server . Now we want to change the test indexer IP to Production IP
Kindly guide us when we create the Custom app for windows , Where we can define the indexer IP . So that we can push the same app in the all servers , Route the traffic to the production .

Thanks in Advance

Tags (1)
0 Karma

aakwah
Builder

Hello,

You need to change "server" parameter in outputs.conf (on universal forwarder) to point to Production indexer, to locate the file run the following command:

grep -R "server" /opt/splunkforwarder/etc/* | grep outputs.conf | grep -v outputs.conf.example | grep -v outputs.conf.spec | grep -v README

Then you should find the outputs.conf file that contains test server IP, change it to production server IP and restart splunk service

Regards

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...