Hello Everyone,
In my environment, I have installed Splunk Enterprise OVA (standalone) and made as a Server and Windows 2012 (with universal forwarder) as client, but there was power suspended and the server had been rebooted with all the configurations, settings which was made all have been refreshed and set to default; So again I have to begin with the fresh configuration such as setting the IP address , mask address and etc.
So what is the correct way to keep these settings or configuration permanent/persistent even after the server reboots.
Tested:
HI @Sagar0511
My name is Anam Siddique and I am the Community Content Specialist for Splunk Answers. Please accept the appropriate answer that worked for you so other members of the community can benefit from it. If none of the answers have worked for you so far please post further comments so someone can help you.
Thanks
I don't understand, you just "restart" the machine and lose all the local confs? Check with the support, maybe try another version.
This should not be happening. It sounds to me that you have a misconfigured Deployment Server that has 2 problems:
1: It is overcontrolling your settings
2: It does not have restartSplunkd
set so that when it does replace your settings, it does not auto-reboot. Then when you reboot the settings come into effect.
Run this command to see if you are a deploymentclient to a DS:
/opt/splunk/bin/splunk btool deploymentclient list --debug
This should return nothing if you are NOT a DS client. If it returns something, then that is who is in control of your splunk configurations.
I agree with @woodcok
Any body can help to give the solution for this issue.
Have you been in touch with support? I believe the Splunk VMware app is paid for so they should be able to guid you through how to install the DCN OVA