Getting Data In

upgrading from lightweight forwarder to universal forwarder

imacdonald2
Path Finder

Just checking we are planning on upgrading a lightweight forwarder to a universal forwarder.
the plan is
install the universal forwarder
create the /opt/splunkforwarder/old_splunk.seed
Set a deployment server in /opt/splunkforwarder/etc/system/local/deploymentclient.conf
start the universal forwarder.

What I am wondering, will the checkpoint file be honored, if I start the server then wait for the deployment server to send apps the universal forwarder. The app contains the indexes and inputs etc for each of the feeds that the server needs.

Thanks

0 Karma
1 Solution

bmacias84
Champion

Yes, the checkpoint file will be honored, but back up your configs as changes don't occur until restart of splunk. Also verify the $SPLUNK_HOME/var/log/splunk/migration.log, this will tell you which files have been modified. What you are mostly concered about is the fishbucket directory.

Here some additional reading:

Migrating_from_a_light_forwarder

Upgradethenixuniversalforwarder

what-is-this-fishbucket-thing - Found this very informative, but a little out of date.

Hope this helps or gets you started.

View solution in original post

bmacias84
Champion

Yes, the checkpoint file will be honored, but back up your configs as changes don't occur until restart of splunk. Also verify the $SPLUNK_HOME/var/log/splunk/migration.log, this will tell you which files have been modified. What you are mostly concered about is the fishbucket directory.

Here some additional reading:

Migrating_from_a_light_forwarder

Upgradethenixuniversalforwarder

what-is-this-fishbucket-thing - Found this very informative, but a little out of date.

Hope this helps or gets you started.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...