Reporting

How to export forwarder configuration

xabidh
New Member

Hi,

I have installed the forwarder in DC and other server as Indexer.
I do not know how was installed.
I would like to export Forwarder configuration because I have to install a new Forwarder with the same configuration to delete the old one.
What files need to be copied / check?

Thanks in advance.

0 Karma
1 Solution

asimagu
Builder

This is usually configured inside the SplunkForwarder app

$SPLUNK_HOME/etc/apps/SplunkForwarder

but it may be that you configured it in a different way...

View solution in original post

0 Karma

xabidh
New Member

Ok, thanks.

Is necessary change something in the Indexer server?

0 Karma

stmyers7941
Path Finder

The indexer needs to have an inputs.conf with [splunktcp://9997] stanza. You can check to see if your indexer is listening with netstat (assuming nix):
~ $ netstat -tnlp | grep 9997
tcp 0 0 0.0.0.0:9997 0.0.0.0:* LISTEN 24504/splunkd

0 Karma

xabidh
New Member

I already have this sentece in inputs.conf.
I supposed that is not needed in the Indexer point to Forwarder...
I see with the comand "netstat -a" something like that:
TCP [IP of indexer]:9997 [IP of forwarder]:62244

Thanks

0 Karma

vincenteous
Communicator

Hi xabidh,

If you want to implement existing configurations from old forwarder to the new one, I suggest you copy the entirety of $SPLUNK_HOME/etc folder. Copying this folders means you copy all installed apps of old forwarder, inputs.conf, outputs.conf, authentication, and other configurations which has previously been defined on the old one.

0 Karma

asimagu
Builder

This is usually configured inside the SplunkForwarder app

$SPLUNK_HOME/etc/apps/SplunkForwarder

but it may be that you configured it in a different way...

0 Karma

xabidh
New Member

Hi,
I have checked all files inside this folder C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder but I cannot find the file where its configured the indexer. What is the file name where should be contained the IP/name of indexer server?

Regards

0 Karma

MuS
SplunkTrust
SplunkTrust

check any available outputs.conf on your forwarder

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...