Reporting

How is linux cloned server Identified After clone-prep-clear-config Script is Run on Master image?

sendhil103
Engager

Hi,

We are using Amazon Linux Workspaces and we incorporated Splunk in the master image to deploy multiple workspaces from the master image. We have followed the directions in the http://docs.splunk.com/Documentation/Splunk/6.3.1/Forwarding/Makeadfpartofasystemimage doc and it works.
however, the cloned images are not reporting to splunk when we go and look at the cloned images' server.conf and inputs.conf file it contains an entry for host name which is different from its host itself. But its not at all reporting to splunk. (but splunk service is running on the newly cloned hosts).

Basically we want to incorporate splunk with Master image itself and deploy it to all. 

Thank you,
Senthil

Labels (1)

logtastic
Explorer

I have this same issue/question. How can you have the host/image itself report to Splunk?

0 Karma

thambisetty
SplunkTrust
SplunkTrust

once you run below command on image then splunk should not start on image.

./splunk clone-prep-clear-config

if splunk services is started then it might have already created instances.cfg,server.conf and inputs.conf with the details of image server.

can you also check, if splunk GUID of Linux image is matching with UF GUID.

————————————
If this helps, give a like below.
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...