Deployment Architecture

Changing Indexer IP in Univerisal Forwader

sumit29
Path Finder

Hi All,

I need help , We have installed universal forwarder in around 20 machines and provided the deployment , Indexder IP . Logs are forwarder to the test server . Now we want to change the test indexer IP to Production IP
Kindly guide us when we create the Custom app for windows , Where we can define the indexer IP . So that we can push the same app in the all servers , Route the traffic to the production .

Thanks in Advance

Tags (1)
0 Karma

aakwah
Builder

Hello,

You need to change "server" parameter in outputs.conf (on universal forwarder) to point to Production indexer, to locate the file run the following command:

grep -R "server" /opt/splunkforwarder/etc/* | grep outputs.conf | grep -v outputs.conf.example | grep -v outputs.conf.spec | grep -v README

Then you should find the outputs.conf file that contains test server IP, change it to production server IP and restart splunk service

Regards

0 Karma
Get Updates on the Splunk Community!

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...