Getting Data In

How to use deployment server to update clients without overriding changes we'll be making to our Splunk Server's IP?

gnoellbn
Explorer

A while ago we have deployed about a 1000+ Universal Forwarder over our network, not knowing about deployment server. So all basic settings are stored in etc/system folder (outputs.conf notably).

Now the issue we have is we will be changing Splunk server's IP, but we cannot use deployment server to update clients as the outputs.conf in etc/system will be overriding all changes we make.

Would anyone have an idea on how we could proceed to change this? I'd also appreciate if we can find a way to remove the outputs.conf settings in etc/system

Thanks

0 Karma
1 Solution

thomrs
Communicator

There are a number of a supported CLI commands. You can script out the changes most likely. I have an install script that sets a number of things this way.

http://docs.splunk.com/Documentation/Splunk/6.2.1/Forwarding/SupportedCLIcommands

View solution in original post

thomrs
Communicator

There are a number of a supported CLI commands. You can script out the changes most likely. I have an install script that sets a number of things this way.

http://docs.splunk.com/Documentation/Splunk/6.2.1/Forwarding/SupportedCLIcommands

gnoellbn
Explorer

Thanks for that, I'll have a look if I can find what I need there

0 Karma

bmacias84
Champion

If you are using DNS entry or FQDN for the Splunk server you could create a cname entry in DNS. If you are on Windows you could write a one time start up script to rename or remove the outputs .conf. Basically your going to have to script the deletion or renaming of the $SPLUNK_HOME/etc/system/local/outputs.conf.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...