Getting Data In

Does anyone have an easy way to define a serverclass based on the universal forwarder version?

ltrand
Contributor

I was wondering if anyone had a way to easily define a serverclass based on the UF version? We are managing our 5 to 6 upgrade and I'm at a loss on how to get Splunk to automagically determine which app to pick up (because of syntax changes in the inputs.conf) so that all logs are correct. I don't want to hand jam a whitelist obviously, so does anyone have the syntax to do this? Or, is everyone putting both in their inputs.conf for their windows clients & letting splunk figure it all out?

0 Karma
1 Solution

ltrand
Contributor

The resolution to this that we found is as follows:

Put seperate stanza's in the UF 5 & UF 6 language with full settings into the same inputs.conf that go to all windows devices. The UF's will error on the lines that they cannot read due to formatting, but will otherwise process as normal.

After migration is complete then old stanza's can be removed.

View solution in original post

0 Karma

ltrand
Contributor

The resolution to this that we found is as follows:

Put seperate stanza's in the UF 5 & UF 6 language with full settings into the same inputs.conf that go to all windows devices. The UF's will error on the lines that they cannot read due to formatting, but will otherwise process as normal.

After migration is complete then old stanza's can be removed.

0 Karma

jrodman
Splunk Employee
Splunk Employee

Does this have to do with windows-specific inputs like event log, wmi, perfmon, etc?

I don't really have a solution. 😞

0 Karma

ltrand
Contributor

Yes it does, but I can see this as an in general issue as our UF deployment grows larger & we have to rely on more & more disparate groups to keep up with agent upgrades (We have several environments where we can't force down an agent & rely on an on-site admin).

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...