Reporting

How is linux cloned server Identified After clone-prep-clear-config Script is Run on Master image?

sendhil103
Engager

Hi,

We are using Amazon Linux Workspaces and we incorporated Splunk in the master image to deploy multiple workspaces from the master image. We have followed the directions in the http://docs.splunk.com/Documentation/Splunk/6.3.1/Forwarding/Makeadfpartofasystemimage doc and it works.
however, the cloned images are not reporting to splunk when we go and look at the cloned images' server.conf and inputs.conf file it contains an entry for host name which is different from its host itself. But its not at all reporting to splunk. (but splunk service is running on the newly cloned hosts).

Basically we want to incorporate splunk with Master image itself and deploy it to all. 

Thank you,
Senthil

Labels (1)

logtastic
Explorer

I have this same issue/question. How can you have the host/image itself report to Splunk?

0 Karma

thambisetty
SplunkTrust
SplunkTrust

once you run below command on image then splunk should not start on image.

./splunk clone-prep-clear-config

if splunk services is started then it might have already created instances.cfg,server.conf and inputs.conf with the details of image server.

can you also check, if splunk GUID of Linux image is matching with UF GUID.

————————————
If this helps, give a like below.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...