We are going through the process of adding more servers to our fleet and monitor them with splunk.
1. Does anyone know an easy way of grabbing a list of all the servers which currently report into splunk?
2. And does anyone know how I can configure a server to report to a newly added splunk server?
It depends of what you want to do :
Here is the classic procedure to add a new indexer to the cluster.
On the new indexer,
On the search-head,
On each forwarders :
Hi I mean "sending logs". We have a number of servers whose log files we can analyse via splunk, I want to know the full list of which servers and how to add a server.
@dina_vaghjiani, Are you looking for getting your new splunk server or forwarders to "report into" a Deployment server or licensing server.
Define "report into" - do you mean that they're sending logs, or that they're deployment clients, or a bit of both?