Installation

How to keep configuration/settings persistent even after the server reboots?

Sagar0511
Explorer

Hello Everyone,

In my environment, I have installed Splunk Enterprise OVA (standalone) and made as a Server and Windows 2012 (with universal forwarder) as client, but there was power suspended and the server had been rebooted with all the configurations, settings which was made all have been refreshed and set to default; So again I have to begin with the fresh configuration such as setting the IP address , mask address and etc.
So what is the correct way to keep these settings or configuration permanent/persistent even after the server reboots.

Tested:

  1. Set the IP address and all other configuration.
  2. Check the sevices
  3. Set up the Universal forwarder again on the client.
  4. Set the Allow rule for the for the IP address in IPtables services.
0 Karma

Anam
Community Manager
Community Manager

HI @Sagar0511

My name is Anam Siddique and I am the Community Content Specialist for Splunk Answers. Please accept the appropriate answer that worked for you so other members of the community can benefit from it. If none of the answers have worked for you so far please post further comments so someone can help you.

Thanks

0 Karma

felipesewaybric
Contributor

I don't understand, you just "restart" the machine and lose all the local confs? Check with the support, maybe try another version.

0 Karma

woodcock
Esteemed Legend

This should not be happening. It sounds to me that you have a misconfigured Deployment Server that has 2 problems:
1: It is overcontrolling your settings
2: It does not have restartSplunkd set so that when it does replace your settings, it does not auto-reboot. Then when you reboot the settings come into effect.

Run this command to see if you are a deploymentclient to a DS:

/opt/splunk/bin/splunk btool deploymentclient list --debug

This should return nothing if you are NOT a DS client. If it returns something, then that is who is in control of your splunk configurations.

vidhyaArumalla
Path Finder

I agree with @woodcok

0 Karma

Sagar0511
Explorer

Any body can help to give the solution for this issue.

0 Karma

jplumsdaine22
Influencer

Have you been in touch with support? I believe the Splunk VMware app is paid for so they should be able to guid you through how to install the DCN OVA

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...