Deployment Architecture

How to push configuration to multiple Heavy forwarders at a time?

sekhar463
Path Finder

hai we are using multiple Heavy forwarders

while doing any configuration in inputs.conf during logs collection doing manually in all heavy forwarders.

is there anyway to update and push configuration for all at once 

we are using deployment server to manage universal forwarders/clients.

how we can use deployment to manage HF also 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sekhar463,

you can manage HSs in the same way of UFs using your Deployment Server:

  • you have to copy apps in $SPLUNK_HOME/etc/deployment-apps
  • create a ServerClass for HFs
  • deploy apps.

Ciao.

Giuseppe

0 Karma

sekhar463
Path Finder

hi @gcusello 

Thank you. we are using /etc/rsyslog.d/gtslog.d/i_inputs.conf for syslogs inputs.

is it possible to push all configuration for syslog onboarding which we are using rsyslog

 

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

as you are managing rsyslog configurations not splunk HF configuration you will need a something else than a Splunk DS. My proposal is to use e.g. ansible for deploy those configurations and do a needed restarts etc. But this is not a issue what we are discussing on splunk community.

r. Ismo

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sekhar463,

as I said, the HF is a forwarder.

So you have to create a TA (containing at least inputs.conf) that reads the files created by your rsyslog and deploy it to the HF using the Deployment Server.

Ciao.

giuseppe

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...