Getting Data In

How to use deployment server to update clients without overriding changes we'll be making to our Splunk Server's IP?

gnoellbn
Explorer

A while ago we have deployed about a 1000+ Universal Forwarder over our network, not knowing about deployment server. So all basic settings are stored in etc/system folder (outputs.conf notably).

Now the issue we have is we will be changing Splunk server's IP, but we cannot use deployment server to update clients as the outputs.conf in etc/system will be overriding all changes we make.

Would anyone have an idea on how we could proceed to change this? I'd also appreciate if we can find a way to remove the outputs.conf settings in etc/system

Thanks

0 Karma
1 Solution

thomrs
Communicator

There are a number of a supported CLI commands. You can script out the changes most likely. I have an install script that sets a number of things this way.

http://docs.splunk.com/Documentation/Splunk/6.2.1/Forwarding/SupportedCLIcommands

View solution in original post

thomrs
Communicator

There are a number of a supported CLI commands. You can script out the changes most likely. I have an install script that sets a number of things this way.

http://docs.splunk.com/Documentation/Splunk/6.2.1/Forwarding/SupportedCLIcommands

gnoellbn
Explorer

Thanks for that, I'll have a look if I can find what I need there

0 Karma

bmacias84
Champion

If you are using DNS entry or FQDN for the Splunk server you could create a cname entry in DNS. If you are on Windows you could write a one time start up script to rename or remove the outputs .conf. Basically your going to have to script the deletion or renaming of the $SPLUNK_HOME/etc/system/local/outputs.conf.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...