Installation

How to upgrade multiple Linux forwarders at the same time?

dinesh2012
Engager

I have more than 50 Linux forwarders, is there a way I can upgrade them at one go or do I need to login stop and untar the new version and start ?

Labels (2)
Tags (2)
0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi dinesh2012,

there is no way to do this within Splunk.
Use any Software distribution or a remote script like the one you can find here http://wiki.splunk.com/Deploying_Splunk_Light_Forwarders or here this one here http://answers.splunk.com/answers/100989/forwarder-installation-script.html

cheers, MuS

View solution in original post

koshyk
Super Champion

If you are asking about Installing Forwarders as such , you need to use external Config management software (like Puppet/Chef) or your admin might have a satellite server who can do it for you. You could write your own scripts which you can give to your admin (Some sample I have written: https://github.com/getkub/SplunkScriplets/tree/master/SplunkForwarders/SPF_Install)

If you are asking about installing Knowledge objects (like apps, configs) , Definitely you need to start using "Deployment Server". Very easy to setup and you can control all your forwarders from a centralised location. Documentation: http://docs.splunk.com/Documentation/Splunk/latest/Updating/Planadeployment

MuS
SplunkTrust
SplunkTrust

Hi dinesh2012,

there is no way to do this within Splunk.
Use any Software distribution or a remote script like the one you can find here http://wiki.splunk.com/Deploying_Splunk_Light_Forwarders or here this one here http://answers.splunk.com/answers/100989/forwarder-installation-script.html

cheers, MuS

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...