A while ago we have deployed about a 1000+ Universal Forwarder over our network, not knowing about deployment server. So all basic settings are stored in etc/system folder (outputs.conf notably).
Now the issue we have is we will be changing Splunk server's IP, but we cannot use deployment server to update clients as the outputs.conf in etc/system will be overriding all changes we make.
Would anyone have an idea on how we could proceed to change this? I'd also appreciate if we can find a way to remove the outputs.conf settings in etc/system
Thanks
There are a number of a supported CLI commands. You can script out the changes most likely. I have an install script that sets a number of things this way.
http://docs.splunk.com/Documentation/Splunk/6.2.1/Forwarding/SupportedCLIcommands
There are a number of a supported CLI commands. You can script out the changes most likely. I have an install script that sets a number of things this way.
http://docs.splunk.com/Documentation/Splunk/6.2.1/Forwarding/SupportedCLIcommands
Thanks for that, I'll have a look if I can find what I need there
If you are using DNS entry or FQDN for the Splunk server you could create a cname entry in DNS. If you are on Windows you could write a one time start up script to rename or remove the outputs .conf. Basically your going to have to script the deletion or renaming of the $SPLUNK_HOME/etc/system/local/outputs.conf.