Reporting

How is linux cloned server Identified After clone-prep-clear-config Script is Run on Master image?

sendhil103
Engager

Hi,

We are using Amazon Linux Workspaces and we incorporated Splunk in the master image to deploy multiple workspaces from the master image. We have followed the directions in the http://docs.splunk.com/Documentation/Splunk/6.3.1/Forwarding/Makeadfpartofasystemimage doc and it works.
however, the cloned images are not reporting to splunk when we go and look at the cloned images' server.conf and inputs.conf file it contains an entry for host name which is different from its host itself. But its not at all reporting to splunk. (but splunk service is running on the newly cloned hosts).

Basically we want to incorporate splunk with Master image itself and deploy it to all. 

Thank you,
Senthil

Labels (1)

logtastic
Explorer

I have this same issue/question. How can you have the host/image itself report to Splunk?

0 Karma

thambisetty
SplunkTrust
SplunkTrust

once you run below command on image then splunk should not start on image.

./splunk clone-prep-clear-config

if splunk services is started then it might have already created instances.cfg,server.conf and inputs.conf with the details of image server.

can you also check, if splunk GUID of Linux image is matching with UF GUID.

————————————
If this helps, give a like below.
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...