In my environment, I have installed Splunk Enterprise OVA (standalone) and made as a Server and Windows 2012 (with universal forwarder) as client, but there was power suspended and the server had been rebooted with all the configurations, settings which was made all have been refreshed and set to default; So again I have to begin with the fresh configuration such as setting the IP address , mask address and etc.
So what is the correct way to keep these settings or configuration permanent/persistent even after the server reboots.
My name is Anam Siddique and I am the Community Content Specialist for Splunk Answers. Please accept the appropriate answer that worked for you so other members of the community can benefit from it. If none of the answers have worked for you so far please post further comments so someone can help you.
This should not be happening. It sounds to me that you have a misconfigured Deployment Server that has 2 problems:
1: It is overcontrolling your settings
2: It does not have
restartSplunkd set so that when it does replace your settings, it does not auto-reboot. Then when you reboot the settings come into effect.
Run this command to see if you are a deploymentclient to a DS:
/opt/splunk/bin/splunk btool deploymentclient list --debug
This should return nothing if you are NOT a DS client. If it returns something, then that is who is in control of your splunk configurations.