Hello comrades,
After my poor research, I found that only heavy forwarder supports props.conf, but it was like 5 or 6 years old posts. I wonder that UF could now support props.conf? Also how do I upgrade to HF?
Many thanks,
yep, the props.conf on the UF is very very limited.
SEDCMD on props.conf is only for HF or indexer etc..
Yes, HF requires a license.
For a heavy forwarder (HF), you should set up one of the following options:
1) Make the HF a slave of a license master. This will give the HF all of the enterprise capabilities - and the HF will consume no license, as long as it does not index data.
2) Install the forwarder license. This will give the HF many enterprise capabilities, but not all. The HF will be able to parse and forward data. However, it will not be permitted to index and it will not be able to act as a deployment server (as an example). This is the option I would usually choose. (Note that the Universal Forwarder has the forwarder license pre-installed.)
answer from - https://community.splunk.com/t5/Getting-Data-In/Do-we-need-a-license-for-Heavy-forwarder/m-p/210451
Sir,
If I can frankly say all I'm trying to do is here.
Configure the Splunk Add-on for Windows - Splunk Documentation
unfortunately there isn't any information about forwarders here.
that page gives very good list of Splunk commands... which step you are stuck exactly..
All commands with SEDCMD
SEDCMD is a big topic and your one line reply is not helping me/us.
maybe you should provide moooore details and ask precise questions.
upvotes/karma points are appreciated by all. thanks.
Sorry for trouble,
As I named myself...
1. Document mentioned that I have to create props.conf in /opt/splunk/deployment.apps/Splunk-TA-windows/local/ ---> created
2. I just copied all lines with SEDCMD and cleared #
and just hoping to config should work.
All this changes made yesterday,
>>> 1. Document mentioned that I have to create props.conf in /opt/splunk/deployment.apps/Splunk-TA-windows/local/ ---> created .....
did you create this on the HF, right?
>>> 2. I just copied all lines with SEDCMD and cleared # and just hoping to config should work.
after updating the props.conf in Hf, did you restart the splunk service on the HF
did you create this on the HF, right?
hehe no, that's why I started asking about HF. So UF cannot take this SEDCMD configs right?
yep, the props.conf on the UF is very very limited.
SEDCMD on props.conf is only for HF or indexer etc..
Sorry one last question.
Do you suggest us to shift to HF or use indexer?
Hi @BoldKnowsNothin ... the UF, still supports, only very limited props.conf tasks.
https://docs.splunk.com/Documentation/Splunk/9.1.1/admin/Propsconf
on this document, just do a control-F and search for universal.. you will get around 8 matches... only these settings are supported.
>>> Also how do I upgrade to HF?
generally you dont want to upgrade a UF to a HF.. you need to install a new/fresh HF separately on a system.
you downlad splunk enterprise package and install it.. and then enable it as a heavy forwarder. let us know if you have doubts.. thanks.
Hello comrade inventsekar,
Thank you for your help, do I need other kind of licensing to use HV?