Getting Data In

upgrading from lightweight forwarder to universal forwarder

imacdonald2
Path Finder

Just checking we are planning on upgrading a lightweight forwarder to a universal forwarder.
the plan is
install the universal forwarder
create the /opt/splunkforwarder/old_splunk.seed
Set a deployment server in /opt/splunkforwarder/etc/system/local/deploymentclient.conf
start the universal forwarder.

What I am wondering, will the checkpoint file be honored, if I start the server then wait for the deployment server to send apps the universal forwarder. The app contains the indexes and inputs etc for each of the feeds that the server needs.

Thanks

0 Karma
1 Solution

bmacias84
Champion

Yes, the checkpoint file will be honored, but back up your configs as changes don't occur until restart of splunk. Also verify the $SPLUNK_HOME/var/log/splunk/migration.log, this will tell you which files have been modified. What you are mostly concered about is the fishbucket directory.

Here some additional reading:

Migrating_from_a_light_forwarder

Upgradethenixuniversalforwarder

what-is-this-fishbucket-thing - Found this very informative, but a little out of date.

Hope this helps or gets you started.

View solution in original post

bmacias84
Champion

Yes, the checkpoint file will be honored, but back up your configs as changes don't occur until restart of splunk. Also verify the $SPLUNK_HOME/var/log/splunk/migration.log, this will tell you which files have been modified. What you are mostly concered about is the fishbucket directory.

Here some additional reading:

Migrating_from_a_light_forwarder

Upgradethenixuniversalforwarder

what-is-this-fishbucket-thing - Found this very informative, but a little out of date.

Hope this helps or gets you started.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...