Splunk Enterprise

What is the best way to reinstall a Universal Forwarder without reindexing events?

ricotries
Communicator

I have run into some cases where the best path forward was to reinstall a Universal Forwarder and point them to a Deployment Server to have a clean set of configurations. The problem is that if the same paths are monitored after the reinstallation, events could be reindexed. I know that I could potentially make a backup of the $SPLUNK_HOME/var/lib/splunk/fishbucket/ before uninstallation and place it on the new UF (Solved: How can I prevent reindexing events after a reinst... - Splunk Community), but when I read some of the data in these files, I see references to the GUID of the current instance of the UF. Wouldn't this create a conflict with the new GUID generated for the new instance of the UF? How does Splunk treat this inconsistency?

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

You can preserve the GUID by copying $SPLUNK_HOME/etc/instance.cfg and restoring it after the re-installation of the UF.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

woodcock
Esteemed Legend

Stop Splunk, delete $SPLUNK_HOME/etc/* and reinstall in the same place.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You can preserve the GUID by copying $SPLUNK_HOME/etc/instance.cfg and restoring it after the re-installation of the UF.

---
If this reply helps you, Karma would be appreciated.

ricotries
Communicator

@richgalloway, should I copy $SPLUNK_HOME/etc/instance.cfg and $SPLUNK_HOME/var/lib/splunk/fishbucket/ before or after the first run? I'd think it should be done before, but wouldn't that mess up with the first run executions?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Copy the files before uninstalling the UF.  Replace the files after re-installing the UF and before the first run.  It won't affect FTR.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Streamline Data Ingestion With Deployment Server Essentials

REGISTER NOW!Every day the list of sources Admins are responsible for gets bigger and bigger, often making the ...

Remediate Threats Faster and Simplify Investigations With Splunk Enterprise Security ...

REGISTER NOW!Join us for a Tech Talk around our latest release of Splunk Enterprise Security 7.2! We’ll walk ...

Introduction to Splunk AI

WATCH NOWHow are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. ...