Deployment Architecture
Highlighted

Update Universal Forwarder

Explorer

How can I update 300 forwarders quickly?
Is there any method?

Highlighted

Re: Update Universal Forwarder

Legend

Hi @edgarsilva01,
What't the operative system of your servers?
Linux UFs are easy to upgrade using a remote script shell that you can find in Community (if not I can send you!).
For Windows UFs, you have to use a SW distribution tool.

Ciao.
Giuseppe

View solution in original post

0 Karma
Highlighted

Re: Update Universal Forwarder

Explorer

Hi Giuseppe

Linux...

If you could share the script I would be very helpful 🙂

Thanks

0 Karma
Highlighted

Re: Update Universal Forwarder

Legend

Hi @edgarsilva01,
see this (even if it's non accepted!) https://answers.splunk.com/answers/786947/install-splunk-forwarder-in-linux-servers.html
Ciao.
Giuseppe

0 Karma
Highlighted

Re: Update Universal Forwarder

Explorer

Hi @gcusello,

I have to update a lot of Windows UF and try the new app in the splunk base (https://splunkbase.splunk.com/app/5003);  this app distribute the installation itself from the Deployment Server to the UF and run the installation.

I did not get the installation to run, it seems the SplunkForwarder Service cannot perform an installation. If I run the scripts manually, it works.

Did you know if an installation via the SplunkForwarder Service is possible?

Thanks

Manuel

0 Karma
Highlighted

Re: Update Universal Forwarder

Communicator

I would recommend using some kind of configuration management system to do this on scale. If you those are Linux (should work on Windows too) I think Ansible is a good solution for this task.

https://underdefense.com/effortless-splunk-universal-forwarders-update-with-ansible/

Highlighted

Re: Update Universal Forwarder

Explorer

Thanks for the fast response, I will check if his is a solution for us.

Manuel

 

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.