Getting Data In

How to use the current Deployment Server to configure remote UFs with a new Deployment Server IP?

Log_wrangler
Builder

Hi,
I have not found the post if it already exists...
But I have to reconfigure a lot of UF(s) to check-in with a new DS.
Unfortunately the original DS was not configured with a FQDN.

Is there a method to send the UFs an app (e.g. "update_DS_IP) that will configure the UF to connect to the new DS (i.e. replace the DS IP)?

Thank you!

richgalloway
SplunkTrust
SplunkTrust

If you current have an app that tells the UFs where to find the DS then all you need to do is update that app with the new DS's address. Each UF will update itself and contact the new DS.

Since you are asking this question, I'll assume you do not have such an app today. You probably have $SPLUNK_HOME/etc/system/local/deploymentclient.conf on each UF. This practice is strongly (perhaps not strongly enough) discouraged for exactly this reason.

Create your app. Call it something like 'org_all_deploymentclient' and push it to all UFs.

Then comes the hard part. You need to delete the $SPLUNK_HOME/etc/system/local/deploymentclient.conf file from every UF. Let's hope you have a centralized way to do that (Puppet, Chef, etc.), otherwise you will have to log in to each UF to delete the file.

---
If this reply helps you, Karma would be appreciated.

nickhills
Ultra Champion

If you're brave...
Scripted input to run a bash script which rm's $SPLUNK_HOME/etc/system/local/deploymentclient.conf
Tried it once. Worked, but didn't sleep for 3 days afterwards.

If my comment helps, please give it a thumbs up!
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...