Getting Data In

How to use the current Deployment Server to configure remote UFs with a new Deployment Server IP?

Log_wrangler
Builder

Hi,
I have not found the post if it already exists...
But I have to reconfigure a lot of UF(s) to check-in with a new DS.
Unfortunately the original DS was not configured with a FQDN.

Is there a method to send the UFs an app (e.g. "update_DS_IP) that will configure the UF to connect to the new DS (i.e. replace the DS IP)?

Thank you!

richgalloway
SplunkTrust
SplunkTrust

If you current have an app that tells the UFs where to find the DS then all you need to do is update that app with the new DS's address. Each UF will update itself and contact the new DS.

Since you are asking this question, I'll assume you do not have such an app today. You probably have $SPLUNK_HOME/etc/system/local/deploymentclient.conf on each UF. This practice is strongly (perhaps not strongly enough) discouraged for exactly this reason.

Create your app. Call it something like 'org_all_deploymentclient' and push it to all UFs.

Then comes the hard part. You need to delete the $SPLUNK_HOME/etc/system/local/deploymentclient.conf file from every UF. Let's hope you have a centralized way to do that (Puppet, Chef, etc.), otherwise you will have to log in to each UF to delete the file.

---
If this reply helps you, Karma would be appreciated.

nickhills
Ultra Champion

If you're brave...
Scripted input to run a bash script which rm's $SPLUNK_HOME/etc/system/local/deploymentclient.conf
Tried it once. Worked, but didn't sleep for 3 days afterwards.

If my comment helps, please give it a thumbs up!
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...