Getting Data In

How to set the site during Universal Forwarder installation for a Splunk 6.3 multisite indexer cluster?

karlbosanquet
Path Finder

I am deploying Universal Forwarders by either Puppet or SCCM to multiple hosts. They will be forwarding to a 6.3.0 multisite indexer cluster.

Is there a way to set site=site0 in the system/local/server.conf to save having to log into each server to update this flag?

0 Karma
1 Solution

maciep
Champion

first off, do you need to set it to that on your universal forwarders. Can't you just configure your outputs.conf to send data to all of your indexers in the cluster? I thought the site0 functionality was just for search head affinity but could be wrong.

That said, you could just deploy an app with your specific server.conf settings along with the uf install. So install install the uf, copy the app to etc/apps and restart splunk.

And depending on how many forwarders you will be managing, you may benefit from implementing the splunk deployment server. Or you could just use puppet/sccm to manage configurations similarly.

View solution in original post

maciep
Champion

first off, do you need to set it to that on your universal forwarders. Can't you just configure your outputs.conf to send data to all of your indexers in the cluster? I thought the site0 functionality was just for search head affinity but could be wrong.

That said, you could just deploy an app with your specific server.conf settings along with the uf install. So install install the uf, copy the app to etc/apps and restart splunk.

And depending on how many forwarders you will be managing, you may benefit from implementing the splunk deployment server. Or you could just use puppet/sccm to manage configurations similarly.

karlbosanquet
Path Finder

Creating an outputs.conf with just the general stanza and site flag in an app which I push from a deployer did the trick.

I am using a multi site index cluster so the outputs.conf created in a barebones install points to the index cluster master which requires site details. The process above means I can deploy a barebones forwarder to any server and update all the required settings via the app deployment process.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...