Installation

Universal Forwarder License changing

jonwick
Path Finder

Hello Splunkers,

I need to reuse universal forwarders which are at earlier were owned by other teams.

We are looking forward to take this decision to avoid unnecessary installation and deinstallation.

I need to change deployment server first is what I understood.

But since we have different Splunk Enterprise License , the forwarder license within UF would be different.

How can we own the splunk UF by license as well.

Is there any way to change it??? Or will it be more efforts to do that instead installing and deinstalling.

Or shall we upgrade it, will it work???

Are their any other trade offs we need to review? (ok with fishbucket one)

 

 

 

Labels (5)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust
Yes you can if you are collecting same stuff as earlier. Just stop UF, copy fish bucket to safe place then remove + install and before you start new one copy old FB back to splunk db dir.
r. Ismo

View solution in original post

gcusello
Legend

Hi @jonwick,

Splunk license is related only to daily indexed logs.

This means that Universal Forwarders don't have any impact on license costs, in other words you can install all the UFs you want.

Obviously more UFs means more logs to index and so more license consuption on Indexers, but anyway you don't pay license for UFs (as other competitor technologies).

It could be a little bit different on Heavy Forwarders bacause if you have a local copy of events you pay this license (really you pay twice this logs!), if insteal you haven't a local copy of logs, Heavy Forwarders are like Universal Forwarders: there's no additional costs for them and you can install all the HFs you want without additional costs.

Ciao.

Giuseppe

0 Karma

jonwick
Path Finder

Hi @gcusello ,

Other team is no more using Splunk setup and have nothing to do with UFs and logs now.

All are universal forwarders,it is just a part of owning the UF, can we change the license of of existing UF??

The forwarder license which we may have is to be put over existing UFs.

Can this be done?

 

 

0 Karma

gcusello
Legend

Hi @jonwick,

sorry but I don't understand what you mean with "forwarder license": there isn't a forwarder license!

You can install all the forwarders you want and there isn't an owner of the forwarder, only the user you're using to run it (root or splunk in Linux, SYSTEM_LOCAL in Windows), but an owner of the process not of the license.

So at your question "can we change the license of of existing UF?" I answer with another question: with which type of license you would like to change the current one?

You can install an Heavy forwarder, usually isn't useful and consume more resources and anyway hasn't still a license.

You can install a Splunk Enterprise, but this hasn'r a sense!

If you want install another Universal Forwarder, there isn't any difference with the previous.

Ciao.

Giuseppe

0 Karma

jonwick
Path Finder

Hi @gcusello ,

License the one mentioned here

https://docs.splunk.com/Documentation/Splunk/8.0.6/Admin/TypesofSplunklicenses#:~:text=The%20Forward...

Anyways it doesn't claim any ownership I  guess, so nothing to worry with these aspects.

0 Karma

gcusello
Legend

Hi @jonwick,

Yes, this is the point.

Ciao.

Giuseppe

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

to be honest, probably the easiest and  the simpliest way is the next:

  1. create new splunk app which point to the new DS
  2. remove old UF installation
  3. install new UF with that new app 
  4. Configure it with your DS

To simplify those step 2&3 use your favourite automation/installation tool like SCCM, ansible, puppet etc.

UF's license just for features. It's not connected to any customer => no need to update it when "owner" will change if you want to reuse current UF.

r. Ismo

jonwick
Path Finder

Hi @isoutamo , can I preserve fishbucket of older one and paste it in new one ?? incase needed to avoid getting logs from the beginning and to pint where earlier one had left off?

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Yes you can if you are collecting same stuff as earlier. Just stop UF, copy fish bucket to safe place then remove + install and before you start new one copy old FB back to splunk db dir.
r. Ismo

View solution in original post

Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!