Activity Feed
- Karma Re: Is there anyway to enable a deployment server on an existing Splunk instance without having to reinstall indexers and forwarders? for ChrisG. 06-05-2020 12:47 AM
- Karma Re: Is there anyway to enable a deployment server on an existing Splunk instance without having to reinstall indexers and forwarders? for alacercogitatus. 06-05-2020 12:47 AM
- Karma Re: Why is deployment client not picking up changes to an app deployed from deployment server? for bkondakindi. 06-05-2020 12:47 AM
- Karma Re: How to update only the inputs.conf blacklist stanza on a universal forwarder with a deployment server? for cpetterborg. 06-05-2020 12:47 AM
- Got Karma for Re: Is there anyway to enable a deployment server on an existing Splunk instance without having to reinstall indexers and forwarders?. 06-05-2020 12:47 AM
- Got Karma for How to update only the inputs.conf blacklist stanza on a universal forwarder with a deployment server?. 06-05-2020 12:47 AM
- Posted Re: How to update only the inputs.conf blacklist stanza on a universal forwarder with a deployment server? on Getting Data In. 03-17-2015 08:38 AM
- Posted Re: How to update only the inputs.conf blacklist stanza on a universal forwarder with a deployment server? on Getting Data In. 03-16-2015 01:10 PM
- Posted How to update only the inputs.conf blacklist stanza on a universal forwarder with a deployment server? on Getting Data In. 03-12-2015 11:34 AM
- Tagged How to update only the inputs.conf blacklist stanza on a universal forwarder with a deployment server? on Getting Data In. 03-12-2015 11:34 AM
- Tagged How to update only the inputs.conf blacklist stanza on a universal forwarder with a deployment server? on Getting Data In. 03-12-2015 11:34 AM
- Tagged How to update only the inputs.conf blacklist stanza on a universal forwarder with a deployment server? on Getting Data In. 03-12-2015 11:34 AM
- Tagged How to update only the inputs.conf blacklist stanza on a universal forwarder with a deployment server? on Getting Data In. 03-12-2015 11:34 AM
- Tagged How to update only the inputs.conf blacklist stanza on a universal forwarder with a deployment server? on Getting Data In. 03-12-2015 11:34 AM
- Posted Re: Is there anyway to enable a deployment server on an existing Splunk instance without having to reinstall indexers and forwarders? on Getting Data In. 03-12-2015 09:59 AM
- Posted Is there anyway to enable a deployment server on an existing Splunk instance without having to reinstall indexers and forwarders? on Getting Data In. 01-06-2015 10:29 AM
- Tagged Is there anyway to enable a deployment server on an existing Splunk instance without having to reinstall indexers and forwarders? on Getting Data In. 01-06-2015 10:29 AM
- Tagged Is there anyway to enable a deployment server on an existing Splunk instance without having to reinstall indexers and forwarders? on Getting Data In. 01-06-2015 10:29 AM
- Tagged Is there anyway to enable a deployment server on an existing Splunk instance without having to reinstall indexers and forwarders? on Getting Data In. 01-06-2015 10:29 AM
- Tagged Is there anyway to enable a deployment server on an existing Splunk instance without having to reinstall indexers and forwarders? on Getting Data In. 01-06-2015 10:29 AM
Topics I've Started
03-17-2015
08:38 AM
Understood.. Re-did configuration so that it deploys to the /local directory to be consistent.
Thanks again for your help with this.
... View more
03-16-2015
01:10 PM
Thank you sir!!! only issue I am seeing now is, instead of etc/apps/MYCONFIGAPP/local/inputs.conf
it is showing up in etc/apps/MYCONFIGAPP/inputs.conf .. would the conf file still be read?
Thanks again!
... View more
03-12-2015
11:34 AM
1 Karma
Have a myriad of webservers in a webfarm where I need to blacklist certain eventIDs/Types (from time to time) to preserve license usage and minimize "clutter" in searches.. It would be very time consuming to update each forwarder individually. (thought of using DFS, but that will change EVERYTHING)
Where I am at now.. Already defined a server class.. Have forwarders inside aforementioned webfarm pointed to deployment server..
Question is.. How can I -only- update the "blacklist stanza" and not host value? Need to keep the host uniquely specified for searching purposes..
My inputs.conf file looks something like this. Again, just want to update the blacklist=XXXX value and leave host = alone?
[default]
host = Server007
[script://$SPLUNK_HOME\bin\scripts\splunk-wmi.path]
disabled = 0
[WinEventLog://Security]
disabled = true
[WinEventLog://System]
disabled = true
[WinEventLog:Application]
disabled = false
blacklist = EventCode="XXXX" Message="Object Type:\s+(?!groupPolicyContainer)"
Thanks in advance for help with this
... View more
03-12-2015
09:59 AM
1 Karma
Ok.. thanks for the help.. Wanted to accept both answers as they helped me get this figured out..
... View more
01-06-2015
10:29 AM
We already have Splunk deployed, (indexer, w/ light forwarders)...
The reason for this question is that we've had issues getting splunk to work, but initially had issues getting data from forwarders. After uninstalling and reinstalling a few times, it finally worked.. somehow.. Which is fine..
Problem is, updating forwarders to blacklist certain events to not exceed license limits (saving bandwidth) is going to be a pain to do this every time manually. Having to update conf files on each server and of course -as we grow- it makes more sense to have a deployment server enabled.
So, is there anyway to enable a deployment server on a splunk instance that is already installed without having to re-install the indexer and forwarder(s)?
If there is a link to help with this, that would be perfect..
Thanks in advance,
Joe
... View more