I'm using Splunk Light 6.2.3 and would like to manage (add to and remove from) a server class I created. The closest I can get is "Data inputs » Event log collections", but the server class link on that page brings me to a "Page not found!". Is this a bug or am I missing something? Thanks.
I'm running into the same thing as the OP. I find it hard to believe that there isn't a way to add additional clients (at separate times) to existing Server Classes. There is an option when you first create the Server Class to add multiple clients, but for the life of me, I can't figure out how to add clients post configuration, or even to remove clients post configuration. I also get the same broken link when I drill down into the depths of the application.
Splunk Light does not support a distributed deployment. Server classes are for the deployment server, to define a set of clients that should receive the same configuration updates.
Backing up...what are you trying to do with the product?
If you cannot use Server Classes in Splunk Light, how else are you supposed to configure Data Inputs without editing conf files or using the CLI? Say I make a Server Class called "Windows Servers" and I add the 5 hosts I have Universal Forwarders on to the group, and then configure "Windows Servers" to monitor Event Logs. Now I add a 6th Windows host and install a Universal Forwarder on it. How can I start collecting Event Logs if I cannot edit the Server Class "Windows Servers" to add this host to it?
The only way I see how is to configure the Universal Forwarder on install to add the monitor (which introduces its own problems), edit the inputs.conf on the forwarder, or edit the conf files on the Splunk server.
All of these solutions are super cumbersome and defeat the purpose of trying to manage things using the web console. Between this and 2-3 other "Splunk Light" specific bugs I have run into during my testing, Splunk Light seems like a half-baked, incomplete solution.
Thanks for the feedback on the Server Classes in Splunk Light. What other Splunk Specific bugs have you run into? We are working on a set of enhancements to Splunk Light and it would be good to get your feedback.
Based on the original documentation the only difference between enterprise and light was the license size, and custom api configurations. Now that we have purchased the light version I'm noticing a lot more restrictions such as the use of apps being limited, server class now, and ease of management.
I have not confirmed this firsthand in an installation of my own, but I believe that the underlying bug has been fixed in the new 6.4 release and you can now edit server classes in Splunk Light.
See this documentation for information about using universal forwarders to get data into your Splunk Light cloud service.
I checked with the product team. Deployment server does not work in Splunk Light today. Because Splunk Light and Splunk Enterprise share a code base and the UI is defined by licensing, there are a few defects where features that are only available in Enterprise partially appear in Light. That is why you are seeing that server class link.