Getting Data In

If we clone a Windows server with a Splunk forwarder installed, how do we configure the the cloned server to send data to Splunk?

omuelle1
Communicator

HI,

I think this is a rather silly question, but I haven't been working with Splunk for too long and just can't figure it out.

We just cloned a Windows box (server1) that has a Splunk forwarder installed that is sending data to Splunk. The clone: server2 has everything server1 had, including the Splunk Forwarder. My question is, how to get the Server2 talking to Splunk and sending Data to Splunk? I cannot locate a file where IPs/Hostnames of Forwarding servers are configured.

When I check under Forwarder Management in the SPLUNK UI, Server2 isn't even being recognized.

Oliver

1 Solution

bdahlb
Explorer

Ideally you want to run the "./splunk clone-prep-clear-config" command as referenced in the Splunk documentation before cloning the server. You can reference this answer to get an idea how to clean up the servername/GUID on the existing clone to get it to generate a new one.

View solution in original post

0 Karma

bdahlb
Explorer

Ideally you want to run the "./splunk clone-prep-clear-config" command as referenced in the Splunk documentation before cloning the server. You can reference this answer to get an idea how to clean up the servername/GUID on the existing clone to get it to generate a new one.

0 Karma

bdahlb
Explorer

Ideally you want to run the "./splunk clone-prep-clear-config" command as referenced in the Splunk documentation "http://docs.splunk.com/Documentation/Splunk/6.3.1/Forwarding/Makeadfpartofasystemimage" before cloning the server. You can reference this answer "https://answers.splunk.com/answers/32368/duplicate-guids-for-cloned-forwarders-how-to-correct.html" to get an idea how to clean up the servername/GUID on the existing clone to get it to generate a new one.

Edit: Hurray for links not working for me!

0 Karma

omuelle1
Communicator

Thank you, I will try that!

0 Karma

omuelle1
Communicator

It did not show up however, I am suspecting it has to do with the server.conf file on the cloned server.

On the cloned server I have exactly the same server,conf file under system/local with the same generated key. Might this be the problem why it couldn't be recognized on the DS ?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...